VYPR
High severity7.2NVD Advisory· Published Feb 6, 2026· Updated Jun 17, 2026

CVE-2026-25754

CVE-2026-25754

Description

AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a prototype pollution vulnerability in AdonisJS multipart form-data parsing may allow a remote attacker to manipulate object prototypes at runtime. This issue has been patched in versions 10.1.3 and 11.0.0-next.9.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
@adonisjs/bodyparsernpm
< 10.1.310.1.3
@adonisjs/bodyparsernpm
>= 11.0.0-next.0, < 11.0.0-next.911.0.0-next.9

Affected products

11
  • cpe:2.3:a:adonisjs:bodyparser:*:*:*:*:*:node.js:*:*+ 8 more
    • cpe:2.3:a:adonisjs:bodyparser:*:*:*:*:*:node.js:*:*range: <10.1.3
    • cpe:2.3:a:adonisjs:bodyparser:11.0.0:next1:*:*:*:node.js:*:*
    • cpe:2.3:a:adonisjs:bodyparser:11.0.0:next2:*:*:*:node.js:*:*
    • cpe:2.3:a:adonisjs:bodyparser:11.0.0:next3:*:*:*:node.js:*:*
    • cpe:2.3:a:adonisjs:bodyparser:11.0.0:next4:*:*:*:node.js:*:*
    • cpe:2.3:a:adonisjs:bodyparser:11.0.0:next5:*:*:*:node.js:*:*
    • cpe:2.3:a:adonisjs:bodyparser:11.0.0:next6:*:*:*:node.js:*:*
    • cpe:2.3:a:adonisjs:bodyparser:11.0.0:next7:*:*:*:node.js:*:*
    • cpe:2.3:a:adonisjs:bodyparser:11.0.0:next8:*:*:*:node.js:*:*
  • ghsa-coords
    Range: < 10.1.3
  • Range: < 10.1.3

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.