logo

Critical AdonisJS Vulnerability Allows Remote Attackers to Write Files on Server

ID: 2fcece48-809b-5a20-9d70-7a1da5158ca7

STIX ID: report--2fcece48-809b-5a20-9d70-7a1da5158ca7

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-01-06

Date Updated: 2026-04-22

Author: Mayura Kathir

...
...

**AdonisJS path traversal (CVE-2026-21440):** A critical path traversal flaw in @adonisjs/bodyparser's MultipartFile.move allows unauthenticated attackers to write files outside the intended upload directory by supplying crafted filenames and relying on default overwrite behavior; affected versions through 10.1.1 and prerelease 11.x prior to 11.0.0-next.6 are fixed in 10.1.2 and 11.0.0-next.6. Immediate upgrades and strict filename sanitization with overwrite explicitly set to false are recommended to mitigate potential file overwrite and remote code execution scenarios.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.