Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Artemis II mission sets stage for lunar return and beyond

APT41-linked Silver Dragon uses Cobalt Strike and Google Drive C2 to target governments

UK allocates £30m to strengthen satellite communications sector

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Critical flaw in AdonisJS Bodyparser (CVSS 9.2) allows arbitrary file writing on the server
Identity

Critical flaw in AdonisJS Bodyparser (CVSS 9.2) allows arbitrary file writing on the server

userBy userJanuary 6, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

January 6, 2026Ravi LakshmananVulnerabilities / Web Security

Users of the ‘@adonisjs/bodyparser’ npm package are advised to update to the latest version following disclosure of a critical security vulnerability that, if successfully exploited, could allow a remote attacker to write arbitrary files on the server.

This flaw is tracked as CVE-2026-21440 (CVSS score: 9.2) and is described as a path traversal issue affecting the AdonisJS multipart file handling mechanism. ‘@adonisjs/bodyparser’ is an npm package associated with AdonisJS, a Node.js framework for developing web apps and API servers using TypeScript. This library is used to process AdonisJS HTTP request bodies.

“If a developer uses MultipartFile.move() without specifying the second optional argument or explicitly sanitizing the filename, an attacker could provide a crafted filename value containing a traversal sequence and write to a destination path outside of the intended upload directory,” project administrators said in an advisory released last week. “This could lead to arbitrary files being written on the server.”

cyber security

However, a successful exploit depends on a reachable upload endpoint. The crux of the problem lies in a function named “MultipartFile.move(location, options)” that allows you to move a file to a specified location. The “options” parameter holds two values: a file name and an override flag that indicates “true” or “false.”

This issue occurs when the name parameter is not passed as input, causing the application to use an unsanitized client file name by default, opening the door to path traversal. This allows an attacker to choose any destination and overwrite sensitive files if the overwrite flag is set to ‘true’.

“If an attacker can overwrite application code, startup scripts, or configuration files that are later executed/loaded, RCE [remote code execution] AdonisJS says, “RCE is not guaranteed and depends on file system permissions, deployment layout, and application/runtime behavior.”

This issue, discovered and reported by Hunter Wodzenski (@wodzen), affects the following versions:

<= 10.1.1 (fixed in 10.1.2) <= 11.0.0-next.5 (fixed in 11.0.0-next.6)

Defects in jsPDF npm library

This development coincides with the disclosure of another path traversal vulnerability in an npm package named jsPDF (CVE-2025-68428, CVSS score: 9.2). This vulnerability could be exploited to traverse unsanitized paths and obtain the contents of arbitrary files in the local file system of a running Node process.

cyber security

This vulnerability was fixed in jsPDF version 4.0.0 released on January 3, 2026. As a workaround, we recommend using the –permission flag to restrict access to the file system. A researcher named Kwangwoon Kim is credited with reporting this bug.

Parallax, developer of the JavaScript PDF generation library, says, “The contents of the file are included intact in the generated PDF.” “Only the node.js build of the library is affected, i.e. the dist/jspdf.node.js and dist/jspdf.node.min.js files.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleInsight Partners sued by former vice president Kate Rowley
Next Article New n8n vulnerability (9.9 CVSS) allows authenticated users to execute system commands
user
  • Website

Related Posts

APT41-linked Silver Dragon uses Cobalt Strike and Google Drive C2 to target governments

March 4, 2026

CISA adds actively exploited VMware Aria operational flaw CVE-2026-22719 to KEV catalog

March 4, 2026

Fake tech support spam deploys customized Havoc C2 across organization

March 3, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Artemis II mission sets stage for lunar return and beyond

APT41-linked Silver Dragon uses Cobalt Strike and Google Drive C2 to target governments

UK allocates £30m to strengthen satellite communications sector

CISA adds actively exploited VMware Aria operational flaw CVE-2026-22719 to KEV catalog

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.