Listen to this Post
The vulnerability resides within the shared `createURL()` helper utilized by AdonisJS route URL builders, including `Router.makeUrl()` and Response.redirect().toRoute(). Specifically, route parameter values and wildcard parameters were previously appended to generated URLs directly without proper URI encoding. When an application passes untrusted, request-derived user input into a route whose first path segment is dynamic, a malicious value starting with a forward slash can alter the URL structure. This causes the framework to produce a scheme-relative URL rather than a local path. Browsers interpret this resulting location value as an external URL and automatically redirect the victim to an attacker-controlled destination, facilitating phishing attacks or compromising authentication and OAuth workflows.
DailyCVE Form:
Platform: AdonisJS
Version: <8.2.3, <9.3.0
Vulnerability : Open Redirect
Severity : Medium
date : 2026-10-08
Prediction : 2026-10-08
What Undercode Say:
bash
Update AdonisJS HTTP server package via npm
npm i @adonisjs/core@latest
javascript
// Vulnerable code implementation example
router.get(‘/:page’, handler).as(‘pages.show’)
response.redirect().toRoute(‘pages.show’, {
page: ‘/evil.example.com’,
})
Exploit: (Educational Purposes!)
An attacker supplies a crafted payload beginning with a slash (e.g., /evil.example.com) as a dynamic route parameter inside an application redirection handler. Because the framework inserts the value without encoding, the generated HTTP response header becomes Location: //evil.example.com. Modern web browsers interpret this double-slash syntax as an absolute scheme-relative external URL, silently redirecting users away from the trusted domain to the malicious external site for phishing or credential harvesting.
Protection:
Upgrade the AdonisJS HTTP server package to version 8.2.3, 9.3.0, or later where route parameters and wildcard values are properly sanitized using `encodeURIComponent()` before being concatenated into URL paths. Avoid passing raw, unvalidated user input directly into dynamic route segments designated for redirection logic.
Impact:
Successful exploitation allows malicious actors to construct deceptive links on trusted enterprise or application domains that seamlessly redirect unsuspecting victims to external, attacker-controlled web infrastructure. This exposes users to targeted phishing campaigns and enables the manipulation or hijacking of sensitive authentication flows and OAuth integrations relying upon trusted domain redirects.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

