{"id":"GHSA-qcm7-3vpr-hj5h","summary":"@adonisjs/bodyparser has an incomplete fix for CVE-2026-25754","details":"### Summary\n\nThe fix for [GHSA-f5x2-vj4h-vg4c](https://github.com/adonisjs/core/security/advisories/GHSA-f5x2-vj4h-vg4c) / CVE-2026-25754 introduced in commit [`40e1c71`](https://github.com/adonisjs/bodyparser/commit/40e1c71f958cffb74f6b91bed6630dca979062ed) is incomplete and can be bypassed through nested prototype pollution payloads.\n\nThe original patch replaced the internal `FormFields` storage object with `Object.create(null)`, preventing direct payloads such as `__proto__.polluted`. However, payloads containing a non-dangerous segment before `__proto__` or `constructor.prototype`, such as `user.__proto__.polluted`, still lead to `Object.prototype` pollution.\n\nThis issue is exploitable remotely through a single unauthenticated `multipart/form-data` request using the default configuration.\n\n### Affected versions\n\n- `\u003e= 10.1.3 \u003c 10.1.5`\n- `\u003e= 11.0.0-next.9 \u003c 11.0.3`\n\n### Details\n\nThe regression tests added by the original fix only covered direct payloads such as:\n\n- `__proto__.polluted`\n- `constructor.prototype.polluted`\n\nThese payloads are blocked because the root object no longer inherits from `Object.prototype`.\n\nHowever, lodash `_.set()` (via `@poppinss/utils`) still creates intermediate objects using plain `{}` values. Once a normal segment is encountered, subsequent `__proto__` or `constructor.prototype` segments regain access to `Object.prototype`.\n\n### Impact\n\nAn unauthenticated attacker can remotely pollute `Object.prototype` on any route accepting multipart/form-data requests behind `BodyParserMiddleware`.\n\nBecause the pollution is process-wide, the impact may include authorization bypasses, unexpected behavior in downstream libraries, or prototype pollution gadget chains leading to remote code execution.\n\n### Patches\n\nFixes targeting v6 and v7 have been published below.\n\nUsers should upgrade to a version that includes the following fix:\n\n- https://github.com/adonisjs/bodyparser/releases/tag/v10.1.5\n- https://github.com/adonisjs/bodyparser/releases/tag/v11.0.3\n\n### References\n\n- [CWE-1321](https://cwe.mitre.org/data/definitions/1321.html)\n- Prior advisory this bypasses: [GHSA-f5x2-vj4h-vg4c](https://github.com/adonisjs/core/security/advisories/GHSA-f5x2-vj4h-vg4c) / CVE-2026-25754","aliases":["CVE-2026-48795"],"modified":"2026-08-24T00:36:59.278120658Z","published":"2026-06-30T18:34:32Z","database_specific":{"cwe_ids":["CWE-1321"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-06-30T18:34:32Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/adonisjs/core/security/advisories/GHSA-f5x2-vj4h-vg4c"},{"type":"WEB","url":"https://github.com/adonisjs/core/security/advisories/GHSA-qcm7-3vpr-hj5h"},{"type":"WEB","url":"https://github.com/adonisjs/bodyparser/commit/40e1c71f958cffb74f6b91bed6630dca979062ed"},{"type":"WEB","url":"https://github.com/adonisjs/bodyparser/releases/tag/v10.1.5"},{"type":"WEB","url":"https://github.com/adonisjs/bodyparser/releases/tag/v11.0.3"},{"type":"PACKAGE","url":"https://github.com/adonisjs/core"}],"affected":[{"package":{"name":"@adonisjs/bodyparser","ecosystem":"npm","purl":"pkg:npm/%40adonisjs/bodyparser"},"ranges":[{"type":"SEMVER","events":[{"introduced":"10.1.3"},{"fixed":"10.1.5"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 10.1.4","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-qcm7-3vpr-hj5h/GHSA-qcm7-3vpr-hj5h.json"}},{"package":{"name":"@adonisjs/bodyparser","ecosystem":"npm","purl":"pkg:npm/%40adonisjs/bodyparser"},"ranges":[{"type":"SEMVER","events":[{"introduced":"11.0.0-next.9"},{"fixed":"11.0.3"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 11.0.1","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-qcm7-3vpr-hj5h/GHSA-qcm7-3vpr-hj5h.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"}]}