AdonisJS HTTP Server, Open Redirect Vulnerability, CVE-2026-107718 (Medium) -DC-Oct2026-2983

Listen to this Post

The vulnerability resides within the shared `createURL()` helper utilized by AdonisJS route URL builders, including `Router.makeUrl()` and Response.redirect().toRoute(). Specifically, route parameter values and wildcard parameters were previously appended to generated URLs directly without proper URI encoding. When an application passes untrusted, request-derived user input into a route whose first path segment is dynamic, a malicious value starting with a forward slash can alter the URL structure. This causes the framework to produce a scheme-relative URL rather than a local path. Browsers interpret this resulting location value as an external URL and automatically redirect the victim to an attacker-controlled destination, facilitating phishing attacks or compromising authentication and OAuth workflows.

DailyCVE Form:

Platform: AdonisJS
Version: <8.2.3, <9.3.0
Vulnerability : Open Redirect
Severity : Medium
date : 2026-10-08

Prediction : 2026-10-08

What Undercode Say:

bash

Update AdonisJS HTTP server package via npm

npm i @adonisjs/core@latest

javascript

// Vulnerable code implementation example

router.get(‘/:page’, handler).as(‘pages.show’)

response.redirect().toRoute(‘pages.show’, {

page: ‘/evil.example.com’,

})

Exploit: (Educational Purposes!)

An attacker supplies a crafted payload beginning with a slash (e.g., /evil.example.com) as a dynamic route parameter inside an application redirection handler. Because the framework inserts the value without encoding, the generated HTTP response header becomes Location: //evil.example.com. Modern web browsers interpret this double-slash syntax as an absolute scheme-relative external URL, silently redirecting users away from the trusted domain to the malicious external site for phishing or credential harvesting.

Protection:

Upgrade the AdonisJS HTTP server package to version 8.2.3, 9.3.0, or later where route parameters and wildcard values are properly sanitized using `encodeURIComponent()` before being concatenated into URL paths. Avoid passing raw, unvalidated user input directly into dynamic route segments designated for redirection logic.

Impact:

Successful exploitation allows malicious actors to construct deceptive links on trusted enterprise or application domains that seamlessly redirect unsuspecting victims to external, attacker-controlled web infrastructure. This exposes users to targeted phishing campaigns and enables the manipulation or hijacking of sensitive authentication flows and OAuth integrations relying upon trusted domain redirects.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top