Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-gvq6-hvvp-h34h | AdonisJS Path Traversal in Multipart File Handling |
Tue, 06 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 02 Jan 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AdonisJS is a TypeScript-first web framework. A Path Traversal vulnerability in AdonisJS multipart file handling may allow a remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This impacts @adonisjs/bodyparser through version 10.1.1 and 11.x prerelease versions prior to 11.0.0-next.6. This issue has been patched in @adonisjs/bodyparser versions 10.1.2 and 11.0.0-next.6. | |
| Title | AdonisJS Path Traversal in Multipart File Handling | |
| Weaknesses | CWE-22 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-05T20:37:47.577Z
Reserved: 2025-12-29T03:00:29.276Z
Link: CVE-2026-21440
Updated: 2026-01-05T20:31:30.704Z
Status : Deferred
Published: 2026-01-02T19:15:48.607
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-21440
No data.
OpenCVE Enrichment
Updated: 2026-04-18T08:45:41Z
Github GHSA