PatchSiren cyber security CVE debrief
CVE-2026-107718 adonisjs CVE debrief
CVE-2026-107718 is an open redirect vulnerability in AdonisJS HTTP Server versions prior to 8.2.3 and 9.3.0. The vulnerability occurs because route parameter values are not properly encoded in URLs, allowing an attacker to redirect users to a malicious site. This issue can facilitate phishing attacks and abuse of authentication flows. Developers and administrators should assess their exposure and take steps to mitigate the vulnerability by upgrading to a fixed version and validating user-controlled data in URLs.
- Vendor
- adonisjs
- Product
- http-server
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Developers and administrators using AdonisJS HTTP Server should assess their exposure and take steps to mitigate the vulnerability. This includes upgrading to a fixed version and validating user-controlled data in URLs. Additionally, security teams and vulnerability management teams should review the vulnerability and its potential impact on their systems.
Why it matters
CVE-2026-107718 is a medium-severity open redirect vulnerability in AdonisJS HTTP Server that can facilitate phishing attacks and abuse of authentication flows. Developers and administrators should upgrade to a fixed version and validate user-controlled data in URLs.
- Phishing attacks may be facilitated through open redirects
- Authentication and OAuth flows may be abused
- Users may be redirected to malicious sites
Technical summary
The AdonisJS HTTP Server package does not properly encode route parameter values in URLs, allowing an attacker to redirect users to a malicious site. This vulnerability affects versions prior to 8.2.3 and 9.3.0. The issue can be mitigated by upgrading to a fixed version and validating user-controlled data in URLs. The vulnerability can facilitate phishing attacks and abuse of authentication flows. To address this vulnerability, developers and administrators should assess their exposure and take steps to mitigate it.
Defensive priority
Medium
Recommended defensive actions
- Upgrade to AdonisJS HTTP Server version 8.2.3 or 9.3.0
- Validate and encode user-controlled data in URLs
- Monitor for potential open redirect attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the vulnerability, including its description, affected versions, and fixed versions. However, there is limited information on potential exploits or attacks. The vulnerability is caused by the lack of proper encoding of route parameter values in URLs, which can lead to open redirects. To verify the vulnerability, defenders should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107718 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107718
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107718 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107718
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
AdonisJS: Unencoded route parameters can produce open redirects
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107718.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/adonisjs/http-server/security/advisories/GHSA-2m6q-8v3h-jqww
Supplemental source - x_refsource_CONFIRM
-
Source reference
Unverified legacy reference
URL: https://github.com/adonisjs/http-server/commit/4548a0631ce2ef1618f04c7b41465be42cad2f7d
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/adonisjs/http-server/commit/ab607a2958327b6f0019d38f26081e431768877a
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/adonisjs/http-server/releases/tag/v8.2.3
Supplemental source - x_refsource_MISC
-
Source reference
Unverified legacy reference
URL: https://github.com/adonisjs/http-server/releases/tag/v9.3.0
Supplemental source - x_refsource_MISC
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.