CVE-2026-25754: Adonisjs Bodyparser

High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.

AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a prototype pollution vulnerability in AdonisJS multipart form-data parsing may allow a remote attacker to manipulate object prototypes at runtime. This issue has been patched in versions 10.1.3 and 11.0.0-next.9.

Affected products

  • Adonisjs Bodyparser: before 10.1.3 (fixed in 10.1.3); from 10.1.4, before 11.0.0 (fixed in 11.0.0); version 11.0.0 only

Published 2026-02-06. Last modified 2026-06-17.