Vulnerability Description
AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompletely fixed CVE-2026-25754 because nested multipart field payloads such as user.__proto__.polluted and constructor.prototype still caused lodash _.set() via @poppinss/utils to create plain intermediate objects and pollute Object.prototype. This issue is fixed in versions 10.1.5 and 11.0.3.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://github.com/adonisjs/bodyparser/commit/8a85eb0c2061b0caca10faedbfc2cf24b5
- https://github.com/adonisjs/bodyparser/commit/aa96908f7b3f64c19e15d2d2d916b69137
- https://github.com/adonisjs/bodyparser/releases/tag/v10.1.5
- https://github.com/adonisjs/bodyparser/releases/tag/v11.0.3
- https://github.com/adonisjs/core/security/advisories/GHSA-qcm7-3vpr-hj5h
FAQ
What is CVE-2026-48795?
CVE-2026-48795 is a vulnerability with a CVSS score of 8.6 (HIGH). AdonisJS is a TypeScript-first web framework. From 10.1.3 until 10.1.5 and 11.0.3, AdonisJS @adonisjs/bodyparser incompletely fixed CVE-2026-25754 because nested multipart field payloads such as user....
How severe is CVE-2026-48795?
CVE-2026-48795 has been rated HIGH with a CVSS base score of 8.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-48795?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.