CVE-2026-21440

Adonisjs Bodyparser < 10.1.2 - Path Traversal

Title source: rule

Description

AdonisJS is a TypeScript-first web framework. A Path Traversal vulnerability in AdonisJS multipart file handling may allow a remote attacker to write arbitrary files to arbitrary locations on the server filesystem. This impacts @adonisjs/bodyparser through version 10.1.1 and 11.x prerelease versions prior to 11.0.0-next.6. This issue has been patched in @adonisjs/bodyparser versions 10.1.2 and 11.0.0-next.6.

Exploits (5)

github WORKING POC 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-21440
nomisec WORKING POC 3 stars
by k0nnect · poc
https://github.com/k0nnect/cve-2026-21440-writeup-poc
nomisec SCANNER 1 stars
by you-ssef9 · poc
https://github.com/you-ssef9/CVE-2026-21440
nomisec WORKING POC
by redpack-kr · poc
https://github.com/redpack-kr/Ashwesker-CVE-2026-21440
nomisec WORKING POC
by TibbersV6 · poc
https://github.com/TibbersV6/CVE-2026-21440-POC-EXP

Scores

EPSS 0.0010
EPSS Percentile 28.5%

Classification

CWE
CWE-22
Status draft

Affected Products (1)

adonisjs/bodyparser < 10.1.2npm

Timeline

Published Jan 02, 2026
Tracked Since Feb 18, 2026