CVE-2026-25754: Adonisjs Bodyparser
High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.
AdonisJS is a TypeScript-first web framework. Prior to versions 10.1.3 and 11.0.0-next.9, a prototype pollution vulnerability in AdonisJS multipart form-data parsing may allow a remote attacker to manipulate object prototypes at runtime. This issue has been patched in versions 10.1.3 and 11.0.0-next.9.
Affected products
- Adonisjs Bodyparser: before 10.1.3 (fixed in 10.1.3); from 10.1.4, before 11.0.0 (fixed in 11.0.0); version 11.0.0 only
Published 2026-02-06. Last modified 2026-06-17.