PatchSiren

adonisjs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM adonisjs CVE published 2026-10-08

CVE-2026-107718

CVE-2026-107718 is an open redirect vulnerability in AdonisJS HTTP Server versions prior to 8.2.3 and 9.3.0. The vulnerability occurs because route parameter values are not properly encoded in URLs, allowing an attacker to redirect users to a malicious site. This issue can facilitate phishing attacks and abuse of authentication flows. Developers and administrators should assess their exposure and take ste [truncated]