PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107718 adonisjs CVE debrief

CVE-2026-107718 is an open redirect vulnerability in AdonisJS HTTP Server versions prior to 8.2.3 and 9.3.0. The vulnerability occurs because route parameter values are not properly encoded in URLs, allowing an attacker to redirect users to a malicious site. This issue can facilitate phishing attacks and abuse of authentication flows. Developers and administrators should assess their exposure and take steps to mitigate the vulnerability by upgrading to a fixed version and validating user-controlled data in URLs.

Vendor
adonisjs
Product
http-server
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Developers and administrators using AdonisJS HTTP Server should assess their exposure and take steps to mitigate the vulnerability. This includes upgrading to a fixed version and validating user-controlled data in URLs. Additionally, security teams and vulnerability management teams should review the vulnerability and its potential impact on their systems.

Why it matters

CVE-2026-107718 is a medium-severity open redirect vulnerability in AdonisJS HTTP Server that can facilitate phishing attacks and abuse of authentication flows. Developers and administrators should upgrade to a fixed version and validate user-controlled data in URLs.

  • Phishing attacks may be facilitated through open redirects
  • Authentication and OAuth flows may be abused
  • Users may be redirected to malicious sites

Technical summary

The AdonisJS HTTP Server package does not properly encode route parameter values in URLs, allowing an attacker to redirect users to a malicious site. This vulnerability affects versions prior to 8.2.3 and 9.3.0. The issue can be mitigated by upgrading to a fixed version and validating user-controlled data in URLs. The vulnerability can facilitate phishing attacks and abuse of authentication flows. To address this vulnerability, developers and administrators should assess their exposure and take steps to mitigate it.

Defensive priority

Medium

Recommended defensive actions

  • Upgrade to AdonisJS HTTP Server version 8.2.3 or 9.3.0
  • Validate and encode user-controlled data in URLs
  • Monitor for potential open redirect attacks
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the vulnerability, including its description, affected versions, and fixed versions. However, there is limited information on potential exploits or attacks. The vulnerability is caused by the lack of proper encoding of route parameter values in URLs, which can lead to open redirects. To verify the vulnerability, defenders should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107718 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107718

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107718 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107718

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • AdonisJS: Unencoded route parameters can produce open redirects

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107718.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/adonisjs/http-server/security/advisories/GHSA-2m6q-8v3h-jqww

    Supplemental source - x_refsource_CONFIRM

  • Source reference

    Unverified legacy reference

    URL: https://github.com/adonisjs/http-server/commit/4548a0631ce2ef1618f04c7b41465be42cad2f7d

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/adonisjs/http-server/commit/ab607a2958327b6f0019d38f26081e431768877a

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/adonisjs/http-server/releases/tag/v8.2.3

    Supplemental source - x_refsource_MISC

  • Source reference

    Unverified legacy reference

    URL: https://github.com/adonisjs/http-server/releases/tag/v9.3.0

    Supplemental source - x_refsource_MISC

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.