GHSA-2m6q-8v3h-jqwwMediumCVSS 6.1

AdonisJS: Unencoded route parameters can produce open redirects

Published
October 8, 2026
Last Modified
October 8, 2026

🔗 CVE IDs covered (1)

📋 Description

Route parameters are inserted into generated URLs without URI encoding.

When an application passes untrusted input to a route whose first path segment is dynamic, a value beginning with / can produce a scheme-relative URL. For example:

router.get('/:page', handler).as('pages.show')

response.redirect().toRoute('pages.show', {
  page: '/evil.example.com',
})

This generates the following redirect:

Location: //evil.example.com

Browsers interpret this value as an external URL and redirect the user to https://evil.example.com.

Details

The shared createURL() helper is used by route URL builders, including Router.makeUrl() and Response.redirect().toRoute().

Route parameter values were appended without encoding:

if (isDefined) {
  uriSegments.push(`${value}${token.end}`)
}

Wildcard parameters had the same behavior:

uriSegments.push(`${values.join('/')}${token.end}`)

The issue does not affect APIs that intentionally accept complete redirect URLs. Exploitation requires an application to pass attacker-controlled data as a route parameter and use the generated URL as a redirect destination.

Impact

An attacker may craft a link on a trusted application domain that redirects a victim to an attacker-controlled website.

This can facilitate phishing and may be chained with authentication or OAuth flows that rely on trusted redirect destinations.

Applications are affected when they:

  • define a route whose first path segment is dynamic; and
  • pass request-derived data to that segment when generating a redirect URL.

Patches

Route parameter values are now encoded using encodeURIComponent.

Wildcard values are encoded individually before being joined with /, preserving their intended segment separators:

if (isDefined) {
  uriSegments.push(`${encodeURIComponent(String(value))}${token.end}`)
}
uriSegments.push(
  `${values.map((value) => encodeURIComponent(String(value))).join('/')}${token.end}`
)

With the fix, /evil.example.com becomes:

/%2Fevil.example.com

Fixes targeting v6 and v7 have been published below.

  • https://github.com/adonisjs/http-server/releases/tag/v8.2.3
  • https://github.com/adonisjs/http-server/releases/tag/v9.3.0

🎯 Affected products2

  • npm/@adonisjs/http-server:>= 9.0.0, <= 9.2.0
  • npm/@adonisjs/http-server:<= 8.2.2

🔗 References (6)