Critical AdonisJS Vulnerability Allows Remote Attackers to Write Files on Server
ID: 2fcece48-809b-5a20-9d70-7a1da5158ca7
STIX ID: report--2fcece48-809b-5a20-9d70-7a1da5158ca7
Feed Name: GBHackers
**AdonisJS path traversal (CVE-2026-21440):** A critical path traversal flaw in @adonisjs/bodyparser's MultipartFile.move allows unauthenticated attackers to write files outside the intended upload directory by supplying crafted filenames and relying on default overwrite behavior; affected versions through 10.1.1 and prerelease 11.x prior to 11.0.0-next.6 are fixed in 10.1.2 and 11.0.0-next.6. Immediate upgrades and strict filename sanitization with overwrite explicitly set to false are recommended to mitigate potential file overwrite and remote code execution scenarios.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
