High severityNVD Advisory· Published Jul 15, 2026· Updated Jul 16, 2026
Incomplete fix for CVE-2026-25754 in @adonisjs/bodyparser
CVE-2026-48795
Description
AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompletely fixed CVE-2026-25754 because nested multipart field payloads such as user.__proto__.polluted and constructor.prototype still caused lodash _.set() via @poppinss/utils to create plain intermediate objects and pollute Object.prototype. This issue is fixed in versions 10.1.5 and 11.0.3.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
@adonisjs/bodyparsernpm | >= 10.1.3, < 10.1.5 | 10.1.5 |
@adonisjs/bodyparsernpm | >= 11.0.0-next.9, < 11.0.3 | 11.0.3 |
Affected products
2- Range: 10.1.3 - 10.1.5, 11.0.3
- Range: 10.1.3 - 10.1.5, 11.0.3
Patches
Vulnerability mechanics
References
8- github.com/advisories/GHSA-qcm7-3vpr-hj5hghsaADVISORY
- github.com/adonisjs/bodyparser/commit/40e1c71f958cffb74f6b91bed6630dca979062edghsaWEB
- github.com/adonisjs/bodyparser/commit/8a85eb0c2061b0caca10faedbfc2cf24b56cf9f6mitrex_refsource_MISC
- github.com/adonisjs/bodyparser/commit/aa96908f7b3f64c19e15d2d2d916b69137bdf469mitrex_refsource_MISC
- github.com/adonisjs/bodyparser/releases/tag/v10.1.5ghsax_refsource_MISCWEB
- github.com/adonisjs/bodyparser/releases/tag/v11.0.3ghsax_refsource_MISCWEB
- github.com/adonisjs/core/security/advisories/GHSA-f5x2-vj4h-vg4cghsaWEB
- github.com/adonisjs/core/security/advisories/GHSA-qcm7-3vpr-hj5hghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.