Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.0 Node.js & npm GHSA-2m6q-8v3h-jqww CVE-2026-107718

Open redirect via unencoded route parameters in @adonisjs/http-server (CVE-2026-107718)

A missing encodeURIComponent call in @adonisjs/http-server's URL helper can allow attacker-controlled first path segments to produce scheme-relative external URLs, enabling open redirects. Fixed in 8.2.3 and 9.3.0. (CVE-2026-107718)

Synthesized by AI from 2 sources · updated 1 hour ago

AI summary

AdonisJS HTTP Server inserts route parameter values into generated URLs without encoding. When applications place untrusted data in a dynamic first path segment and use the framework-generated route URL for redirects, a value beginning with a slash can produce a scheme-relative external URL and cause an open redirect. The issue is tracked as CVE-2026-107718 and fixed in the vendor updates listed below.

What happened

The package @adonisjs/http-server used a shared createURL() helper (used by Router.makeUrl() and Response.redirect().toRoute()) that inserted route parameter values into URLs without calling encodeURIComponent. If an application puts attacker-controlled data into a dynamic first path segment and then redirects to the generated route URL, a value beginning with a slash can lead to a scheme-relative external URL and an open redirect. Wildcard parameters are also affected; APIs that intentionally accept complete redirect URLs are not affected.

Technical cause

The root cause is missing URL-encoding of route parameter values in the shared createURL() helper. That missing encodeURIComponent call allowed raw parameter text (including a leading slash) to be inserted into generated URLs, enabling creation of external redirect targets from values supplied by an application.

Why it matters

An attacker able to influence a dynamic first path segment in affected applications can cause users to be redirected from a trusted site to an attacker-controlled site. This can facilitate phishing and abuse of authentication or OAuth flows. The issue is classified under CWE-601 (Open Redirect).

Who is affected

Applications that use @adonisjs/http-server and place untrusted data into a dynamic first path segment of generated route URLs are at risk. The advisory lists two affected code lines: a range introduced at version "0" and fixed in "8.2.3", and a separate range introduced at "9.0.0" and fixed in "9.3.0"—see affected versions below.

Discovery and timeline

The vulnerability was published in the OSV and NVD entries linked below on 2026-10-08 and the advisory record was updated on 2026-10-09.

Affected versions

Two affected ranges are reported for @adonisjs/http-server: introduced at "0" and fixed in "8.2.3"; and introduced at "9.0.0" and fixed in "9.3.0". Use the range that corresponds to the branch you run.

Fixes and mitigation

Vendor fixes are available: the issue is fixed in "8.2.3" and in "9.3.0" for the respective affected ranges. The advisory marks a fix as available.

Recommended action

Update @adonisjs/http-server to the vendor-fixed release that applies to your deployment ("8.2.3" or "9.3.0"). If you cannot update immediately, avoid placing untrusted values into a dynamic first path segment used to generate redirect URLs, and ensure route parameters are encoded or validated before use.

PatchBriefing score

4.0 / 10 · Medium

Official CVSS: 6.1

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Why this score

CVSS v3.1 base score is 6.1 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N). Patchwire score is 4. The advisory's scoring factors include an unauthenticated remote impact contribution and no known public exploit or known exploitation reported in the sources.

Affected versions

@adonisjs/http-server ≥ 0 < 8.2.3
vulnerable
≥ 8.2.3
patched
≥ 9.3.0
patched

Reported fixes

Vendor fixes are available: the issue is fixed in "8.2.3" and in "9.3.0" for the respective affected ranges. The advisory marks a fix as available.

How this was built

2 source records were collected, matched and used to prepare the report above.

  • OSV.dev database
  • NVD (NIST) database
Unified report
Open redirect via unencoded route parameters in @adonisjs/http-server (CVE-2026-107718)
1 article · 2 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email