PT-2026-6810 · Adonisjs+1 · Adonisjs+1
Romain Lanz
·
Publicado
2026-02-06
·
Atualizado
2026-02-09
·
CVE-2026-25754
CVSS v3.1
7.2
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
AdonisJS versions prior to 10.1.3
AdonisJS versions 11.0.0-next.0 through 11.0.0-next.8
Description
A prototype pollution issue in AdonisJS multipart form-data parsing could allow a remote attacker to manipulate object prototypes during runtime. The vulnerability is limited to multipart request parsing and does not affect JSON or URL-encoded body parsing. Exploitation requires an application endpoint that accepts and parses
multipart/form-data requests. If exploited, prototype pollution may lead to unexpected application behavior or logic bypasses, depending on how polluted objects are consumed. The vulnerability impacts the @adonisjs/bodyparser package through version 10.1.2 and 11.x prerelease versions prior to 11.0.0-next.9.Recommendations
Upgrade to AdonisJS version 10.1.3 or later.
Upgrade to AdonisJS version 11.0.0-next.9 or later.
Exploit
Correção
Prototype Pollution
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
@Adonisjs/Bodyparser
Adonisjs