PT-2026-1121 · Adonisjs+1 · Adonisjs+1

Wodzen

·

Published

2026-01-02

·

Updated

2026-02-07

·

CVE-2026-21440

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:N/I:C/A:C
Name of the Vulnerable Software and Affected Versions AdonisJS versions through 10.1.1 and 11.x prerelease versions prior to 11.0.0-next.6
Description A Path Traversal vulnerability exists in the AdonisJS multipart file handling process. This flaw allows a remote attacker to write arbitrary files to arbitrary locations on the server filesystem. The vulnerability is present in the @adonisjs/bodyparser package. Exploitation involves crafted upload filenames, potentially leading to remote code execution (RCE) if the MultipartFile.move() function is used without proper sanitization. Approximately 44,500 potentially affected systems have been identified. The vulnerability allows attackers to bypass file upload restrictions and overwrite system files, potentially leading to full control over the compromised system.
Recommendations Update to @adonisjs/bodyparser version 10.1.2 or later. Update to @adonisjs/bodyparser version 11.0.0-next.6 or later. Ensure strict server-side filename validation is enforced to prevent path traversal attacks. Avoid enabling overwrite functionality unless absolutely necessary.

Exploit

Fix

RCE

Path traversal

Weakness Enumeration

Related Identifiers

BDU:2026-00120
CVE-2026-21440
GHSA-GVQ6-HVVP-H34H

Affected Products

@Adonisjs/Bodyparser
Adonisjs