{"id":"CVE-2026-21440","aliases":["GHSA-gvq6-hvvp-h34h"],"url":"https://o3.security/vulnerability/CVE-2026-21440","summary":"AdonisJS Path Traversal in Multipart File Handling","details":"AdonisJS is a TypeScript-first web framework. A Path Traversal vulnerability in AdonisJS multipart file handling may allow a remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This impacts @adonisjs/bodyparser through version 10.1.1 and 11.x prerelease versions prior to 11.0.0-next.6. This issue has been patched in @adonisjs/bodyparser versions 10.1.2 and 11.0.0-next.6.","published":"2026-01-02T19:02:18.393Z","modified":"2026-08-07T11:31:27.732276174Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@adonisjs/bodyparser","fixedVersion":"10.1.2"},{"ecosystem":"npm","name":"@adonisjs/bodyparser","fixedVersion":"11.0.0-next.6"}],"fix":{"url":"https://github.com/adonisjs/bodyparser/commit/143a16f35602be8561215611582211dec280cae6","label":"adonisjs/bodyparser@143a16f"},"references":[{"type":"WEB","url":"https://github.com/adonisjs/bodyparser/releases/tag/v10.1.2"},{"type":"WEB","url":"https://github.com/adonisjs/bodyparser/releases/tag/v11.0.0-next.6"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/21xxx/CVE-2026-21440.json"},{"type":"ADVISORY","url":"https://github.com/adonisjs/core/security/advisories/GHSA-gvq6-hvvp-h34h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-21440"},{"type":"FIX","url":"https://github.com/adonisjs/bodyparser/commit/143a16f35602be8561215611582211dec280cae6"},{"type":"FIX","url":"https://github.com/adonisjs/bodyparser/commit/6795c0e3fa824ae275bbd992aae60609e96f0f03"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:27.732276174Z"}}