Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-f5x2-vj4h-vg4c | AdonisJS multipart body parsing has Prototype Pollution issue |
Tue, 17 Mar 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:adonisjs:bodyparser:*:*:*:*:*:node.js:*:* cpe:2.3:a:adonisjs:bodyparser:11.0.0:next1:*:*:*:node.js:*:* cpe:2.3:a:adonisjs:bodyparser:11.0.0:next2:*:*:*:node.js:*:* cpe:2.3:a:adonisjs:bodyparser:11.0.0:next3:*:*:*:node.js:*:* cpe:2.3:a:adonisjs:bodyparser:11.0.0:next4:*:*:*:node.js:*:* cpe:2.3:a:adonisjs:bodyparser:11.0.0:next5:*:*:*:node.js:*:* cpe:2.3:a:adonisjs:bodyparser:11.0.0:next6:*:*:*:node.js:*:* cpe:2.3:a:adonisjs:bodyparser:11.0.0:next7:*:*:*:node.js:*:* cpe:2.3:a:adonisjs:bodyparser:11.0.0:next8:*:*:*:node.js:*:* |
Mon, 09 Feb 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 09 Feb 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Adonisjs
Adonisjs bodyparser |
|
| Vendors & Products |
Adonisjs
Adonisjs bodyparser |
Fri, 06 Feb 2026 23:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a prototype pollution vulnerability in AdonisJS multipart form-data parsing may allow a remote attacker to manipulate object prototypes at runtime. This issue has been patched in versions 10.1.3 and 11.0.0-next.9. | |
| Title | AdonisJS multipart body parsing has Prototype Pollution issue | |
| Weaknesses | CWE-1321 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-09T15:26:12.060Z
Reserved: 2026-02-05T18:35:52.357Z
Link: CVE-2026-25754
Updated: 2026-02-09T15:21:50.322Z
Status : Analyzed
Published: 2026-02-06T23:15:54.390
Modified: 2026-03-17T20:42:28.537
Link: CVE-2026-25754
No data.
OpenCVE Enrichment
Updated: 2026-04-17T22:30:29Z
Github GHSA