Oct 9, 2026·6 min read·1 visit
Unsanitized interpolation of route parameters in AdonisJS HTTP Server allows remote attackers to force protocol-relative redirects, directing users to external malicious domains.
CVE-2026-107718 is a medium-severity Open Redirect vulnerability in the core HTTP server package of the AdonisJS Node.js framework. Prior to versions 8.2.3 and 9.3.0, the framework built route paths by directly interpolating dynamic parameters and wildcard segments without URI encoding. If an application routes attacker-controlled input directly to a dynamic first path segment and uses the generated route URL as a redirect destination, a leading slash can produce a scheme-relative external URL. Modern web browsers process scheme-relative URLs by redirecting the client to the specified external domain, exposing users to credential harvesting, social engineering, and session hijacking. This vulnerability affects all applications running unpatched configurations where input validation is not explicitly implemented before generating paths.
The AdonisJS HTTP Server framework component manages HTTP routing, request parsing, and redirection mechanisms within the AdonisJS ecosystem. To facilitate rapid route navigation and dynamic path generation, the framework exposes helper utility methods such as Router.makeUrl() and Response.redirect().toRoute(). These helpers rely internally on a shared builder function called createURL() to dynamically interpolate variables into registered route patterns.
Prior to the release of patched versions, the framework failed to apply URI encoding to route parameter values before appending them to the generated URL path. This omission creates a direct attack surface in applications that pass untrusted input into dynamic path parameters of a route template, subsequently utilizing that generated path to redirect users. This pattern is common in post-authentication routing and multi-page form tracking.
An attacker can exploit this oversight by crafting dynamic parameter payloads starting with a forward slash. When processed, this injection leads to the generation of a protocol-relative URL string that points to an external destination. Modern web browsers interpret protocol-relative URLs as absolute destinations, transferring the client's session control to an attacker-controlled host.
The root cause of CVE-2026-107718 lies in the string construction logic within the createURL() helper function in src/client/helpers.ts. When resolving a named route, the function iterates over the parameters defined in the route pattern and substitutes placeholder tokens with developer-provided variables. During this substitution, the parameter values were appended directly as raw strings without validation or sanitization.
Under standard conditions, dynamic parameters represent local path segments, such as resource identifiers or category names. However, when the dynamic parameter is located at the first position of the route pattern, the lack of encoding presents a structural hazard. Under normal behavior, a route like /:page with parameter home resolves safely to /home.
When an input parameter starts with a forward slash, such as /evil.example.com, the dynamic replacement appends this raw string to the root path separator. The resulting path becomes //evil.example.com. In accordance with RFC 3986 section 4.2, a path beginning with two slashes is parsed as a network-path reference, or a scheme-relative URL. Modern user agents resolve such links using the base origin's active scheme, converting the local route redirect into a cross-origin redirect.
An analysis of the patch commits, specifically 4548a0631ce2ef1618f04c7b41465be42cad2f7d, reveals a correction of the interpolation mechanics in src/client/helpers.ts. The developers introduced native encodeURIComponent wrapper calls to process both standard dynamic parameters and wildcard parameters before they are integrated into the final URL string.
// Affected interpolation logic before the patch
if (isDefined) {
uriSegments.push(`${value}${token.end}`)
}// Patched interpolation logic enforcing URI encoding
if (isDefined) {
uriSegments.push(`${encodeURIComponent(String(value))}${token.end}`)
}For wildcard segments, the developers mapped the input array to ensure that each component is individually encoded before they are reconstructed using a safe join operation. This change ensures that dynamic elements cannot inject structural path separators. It prevents an attacker from supplying forward slashes to forge scheme-relative or absolute external links. Dynamic inputs containing slashes are neutralized to %2F, which forces the browser to evaluate the parameter strictly as a local directory resource on the original host.
To successfully exploit this vulnerability, the target application must utilize dynamic parameters as part of a route-generation sequence that terminates in an HTTP redirection. This pattern is often implemented in login, logout, or session routing parameters that direct users to a dynamic subpage post-execution.
During an active exploit attempt, an attacker distributes a crafted hyperlink targeting the vulnerable application's login handler. The link includes a payload in the redirection parameter pointing to a phishing website. When the user logs in, the backend computes the redirection URL using response.redirect().toRoute('pages.show', { page: user_provided_payload }). Because of the missing validation, the backend issues an HTTP 302 response with the Location: //malicious-phishing-host.com header. The user's browser automatically loads the phishing website under the assumption that it is a secure continuation of the original transaction.
The security impact of CVE-2026-107718 is classified as Medium, receiving a CVSS v3.1 score of 6.1. The primary risk associated with open redirection is the facilitation of highly convincing phishing campaigns. Because the initial URL points to a legitimate, trusted domain, security gateways, email filters, and trained users are likely to permit the traffic. The downstream redirect is executed automatically without presenting warning notices to the victim.
Beyond credential harvesting, this vulnerability poses risks to OAuth state configurations and single sign-on (SSO) integrations. If the application exposes a vulnerable redirection path that processes dynamic input, an attacker can hijack authentication response codes. This is achieved by redirecting the authentication callback parameter to an external server under their control.
Additionally, this bug can expose sensitive cookies, authorization headers, or referer headers. When the victim browser navigates to the malicious external domain, it may transmit contextual information from the trusted origin in the request headers, leading to potential session exposure.
The definitive remediation for CVE-2026-107718 is updating the @adonisjs/http-server dependency. For codebases built on the 8.x branch, upgrade the package to version 8.2.3 or later. For modern codebases built on the 9.x branch, upgrade the package to version 9.3.0 or later. This introduces the encoding mechanisms required to prevent parameter breakouts.
If immediate dependency updates are not feasible, you can deploy a Web Application Firewall (WAF) rule to block incoming request URIs that contain percent-encoded slashes (%2F) or backslashes (%5C) within routing parameters that are known to drive redirection logic. Developers should also implement strict whitelist validation on the application layer, validating that any redirect parameters resolve strictly to a predefined list of allowed internal paths.
> [!NOTE]
> It is recommended to perform post-upgrade testing. Run npm list @adonisjs/http-server to verify that no legacy, vulnerable versions of the package remain in your project's dependency tree, which can occur due to strict lockfile configurations.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N| Product | Affected Versions | Fixed Version |
|---|---|---|
@adonisjs/http-server AdonisJS | < 8.2.3 | 8.2.3 |
@adonisjs/http-server AdonisJS | >= 9.0.0, < 9.3.0 | 9.3.0 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-601: URL Redirection to Untrusted Site ('Open Redirect') |
| Attack Vector | Network |
| CVSS Score | 6.1 (Medium) |
| EPSS Score | N/A |
| Exploit Status | Proof-of-Concept |
| CISA KEV Status | Not Listed |
The web application accepts a user-controlled input that specifies a link to an external site, and uses this link in a redirect, enabling spoofing and phishing attempts.
CVE-2026-107725 is a critical security bypass in Hazelcast where missing authorization checks in the MapPermission class permit unprivileged clients to issue queries containing aggregators or projections. This architectural oversight allows attackers to run arbitrary code on the cluster servers under the privileges of the active Hazelcast process.
A stored Cross-Site Scripting (XSS) vulnerability was identified in Indico, an open-source event management system developed at CERN, prior to version 3.3.13. The vulnerability stems from weak URL validation in custom link fields and lack of HTML sanitization during Marshmallow serialization of event notes. This allows authenticated attackers with event modification privileges to inject malicious payloads that execute in the browser of users viewing the event pages or collaborating on notes.
A technical analysis of CVE-2026-107397, a stored Cross-Site Scripting (XSS) vulnerability in Indico's collaborative notes editor and custom link generation fields. Prior to version 3.3.13, Marshmallow serialization schemas omitted HTML sanitization during conflict resolution, and form validators failed to enforce strict URI schemes, enabling authenticated low-privilege attackers to execute arbitrary JavaScript.
An authorization bypass vulnerability exists in the legacy session export API of Indico, an open-source event management system developed at CERN. Due to a missing object-level access check, authenticated users can bypass configuration-level restrictions to extract private session metadata (including session titles, descriptions, and list of conveners) from events that they are otherwise authorized to view.
An incomplete Server-Side Request Forgery (SSRF) validation check in Indico prior to version 3.3.13 allows authenticated event organizers to bypass outbound network restrictions. By utilizing backslash characters within crafted URLs, attackers can exploit a parser differential between the application's validator and the downstream HTTP client library to access internal network resources.
CVE-2026-107717 represents a critical prompt boundary bypass and chat role injection vulnerability in the Banks Python package (versions prior to 2.5.0). The library parses generated template outputs line-by-line, attempting to validate each segment as a JSON-serialized ChatMessage object without validating the source boundaries of the text. If an application integrates user input directly into a prompt template, a remote, unauthenticated attacker can supply multi-line inputs with structured JSON payloads. This input is then parsed as high-privilege system instructions or tool execution responses, completely hijacking downstream Large Language Model behavior.