CVE-2026-61526
MEDIUMAdonisJS HTTP Server is vulnerable to reflected XSS through its exception handler
Title source: cnaDescription
AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In versions 8.0.0-next.0 through 8.2.0 and 9.0.0 through 9.0.2, the error.message is interpolated into the default HTML exception response without escaping, allowing a crafted missing-route URL to execute attacker-controlled JavaScript when a victim opens it and no custom status page or JSON response handles the error. When debug mode is disabled and no custom status page handles the error, the default HTML renderer interpolates error.message directly into an HTML response. This issue is fixed in versions 8.2.1 and 9.1.0.
References (5)
Core 5
Core References
X_Refsource_Confirm x_refsource_confirm
https://github.com/adonisjs/http-server/security/advisories/GHSA-cwm9-gfhc-46f6
X_Refsource_Misc x_refsource_misc
https://github.com/adonisjs/http-server/commit/5d7465d599753b1fce8a36da18955f2c273e4f87
X_Refsource_Misc x_refsource_misc
https://github.com/adonisjs/http-server/commit/71a0a8e375c375e3588ba44ef68b0ef5a993c3d3
X_Refsource_Misc x_refsource_misc
https://github.com/adonisjs/http-server/releases/tag/v8.2.1
X_Refsource_Misc x_refsource_misc
https://github.com/adonisjs/http-server/releases/tag/v9.1.0
Scores
CVSS v3
6.1
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
adonisjs/http-server
>= 8.0.0-next.0, < 8.2.1
adonisjs/http-server
>= 9.0.0, < 9.1.0
Published
Jul 30, 2026
Tracked Since
Jul 31, 2026