CVE-2026-107718: AdonisJS: Unencoded route parameters can produce open redirects
Route parameters are inserted into generated URLs without URI encoding.
When an application passes untrusted input to a route whose first path segment is dynamic, a value beginning with / can produce a scheme-relative URL. For example:
router.get('/:page', handler).as('pages.show')
response.redirect().toRoute('pages.show', {
page: '/evil.example.com',
})
This generates the following redirect:
Location: //evil.example.com
Browsers interpret this value as an external URL and redirect the user to https://evil.example.com.
References
- github.com/adonisjs/http-server/commit/4548a0631ce2ef1618f04c7b41465be42cad2f7d
- github.com/adonisjs/http-server/commit/ab607a2958327b6f0019d38f26081e431768877a
- github.com/adonisjs/http-server/releases/tag/v8.2.3
- github.com/adonisjs/http-server/releases/tag/v9.3.0
- github.com/adonisjs/http-server/security/advisories/GHSA-2m6q-8v3h-jqww
- github.com/advisories/GHSA-2m6q-8v3h-jqww
- nvd.nist.gov/vuln/detail/CVE-2026-107718
Code Behaviors & Features
Detect and mitigate CVE-2026-107718 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →