Medium · 4.0 Node.js & npm GHSA-2m6q-8v3h-jqww CVE-2026-107718
Open redirect via unencoded route parameters in @adonisjs/http-server (CVE-2026-107718)
A missing encodeURIComponent call in @adonisjs/http-server's URL helper can allow attacker-controlled first path segments to produce scheme-relative external URLs, enabling open redirects. Fixed in 8.2.3 and 9.3.0. (CVE-2026-107718)
AI summary
AdonisJS HTTP Server inserts route parameter values into generated URLs without encoding. When applications place untrusted data in a dynamic first path segment and use the framework-generated route URL for redirects, a value beginning with a slash can produce a scheme-relative external URL and cause an open redirect. The issue is tracked as CVE-2026-107718 and fixed in the vendor updates listed below.
What happened
The package @adonisjs/http-server used a shared createURL() helper (used by Router.makeUrl() and Response.redirect().toRoute()) that inserted route parameter values into URLs without calling encodeURIComponent. If an application puts attacker-controlled data into a dynamic first path segment and then redirects to the generated route URL, a value beginning with a slash can lead to a scheme-relative external URL and an open redirect. Wildcard parameters are also affected; APIs that intentionally accept complete redirect URLs are not affected.
Technical cause
The root cause is missing URL-encoding of route parameter values in the shared createURL() helper. That missing encodeURIComponent call allowed raw parameter text (including a leading slash) to be inserted into generated URLs, enabling creation of external redirect targets from values supplied by an application.
Why it matters
An attacker able to influence a dynamic first path segment in affected applications can cause users to be redirected from a trusted site to an attacker-controlled site. This can facilitate phishing and abuse of authentication or OAuth flows. The issue is classified under CWE-601 (Open Redirect).
Who is affected
Applications that use @adonisjs/http-server and place untrusted data into a dynamic first path segment of generated route URLs are at risk. The advisory lists two affected code lines: a range introduced at version "0" and fixed in "8.2.3", and a separate range introduced at "9.0.0" and fixed in "9.3.0"—see affected versions below.
Discovery and timeline
The vulnerability was published in the OSV and NVD entries linked below on 2026-10-08 and the advisory record was updated on 2026-10-09.
Affected versions
Two affected ranges are reported for @adonisjs/http-server: introduced at "0" and fixed in "8.2.3"; and introduced at "9.0.0" and fixed in "9.3.0". Use the range that corresponds to the branch you run.
Fixes and mitigation
Vendor fixes are available: the issue is fixed in "8.2.3" and in "9.3.0" for the respective affected ranges. The advisory marks a fix as available.
Recommended action
Update @adonisjs/http-server to the vendor-fixed release that applies to your deployment ("8.2.3" or "9.3.0"). If you cannot update immediately, avoid placing untrusted values into a dynamic first path segment used to generate redirect URLs, and ensure route parameters are encoded or validated before use.
PatchBriefing score
4.0 / 10 · Medium
Official CVSS: 6.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Why this score
CVSS v3.1 base score is 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Patchwire score is 4. The advisory's scoring factors include an unauthenticated remote impact contribution and no known public exploit or known exploitation reported in the sources.
Affected versions
- @adonisjs/http-server ≥ 0 < 8.2.3
- vulnerable
- ≥ 8.2.3
- patched
- ≥ 9.3.0
- patched
Reported fixes
Vendor fixes are available: the issue is fixed in "8.2.3" and in "9.3.0" for the respective affected ranges. The advisory marks a fix as available.
How this was built
2 source records were collected, matched and used to prepare the report above.
-
OSV.dev database
-
NVD (NIST) database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email