CVE-2026-25754
EUVD-2026-693106.02.2026, 23:15
AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a prototype pollution vulnerability in AdonisJS multipart form-data parsing may allow a remote attacker to manipulate object prototypes at runtime. This issue has been patched in versions 10.1.3 and 11.0.0-next.9.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| adonisjs | bodyparser | 𝑥 < 10.1.3 |
| adonisjs | bodyparser | 10.1.4 ≤ 𝑥 < 11.0.0 |
| adonisjs | bodyparser | 11.0.0:next1 |
| adonisjs | bodyparser | 11.0.0:next2 |
| adonisjs | bodyparser | 11.0.0:next3 |
| adonisjs | bodyparser | 11.0.0:next4 |
| adonisjs | bodyparser | 11.0.0:next5 |
| adonisjs | bodyparser | 11.0.0:next6 |
| adonisjs | bodyparser | 11.0.0:next7 |
| adonisjs | bodyparser | 11.0.0:next8 |
𝑥
= Vulnerable software versions