{"id":"CVE-2026-48795","title":"@adonisjs/bodyparser has an incomplete fix for CVE-2026-25754","summary":"@adonisjs/bodyparser has an incomplete fix for CVE-2026-25754","severity":"high","cvss":8.6,"cwe":["CWE-1321"],"vendor":"adonisjs","product":"@adonisjs/bodyparser","ecosystem":"npm","affected":["@adonisjs/bodyparser >= 10.1.3, <= 10.1.4","@adonisjs/bodyparser >= 11.0.0-next.9, <= 11.0.1"],"patched":["@adonisjs/bodyparser 10.1.5","@adonisjs/bodyparser 11.0.3"],"published":"2026-06-30","updated":"2026-06-30","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-qcm7-3vpr-hj5h","references":[{"url":"https://github.com/adonisjs/core/security/advisories/GHSA-f5x2-vj4h-vg4c"},{"url":"https://github.com/adonisjs/core/security/advisories/GHSA-qcm7-3vpr-hj5h"},{"url":"https://github.com/adonisjs/bodyparser/commit/40e1c71f958cffb74f6b91bed6630dca979062ed"},{"url":"https://github.com/adonisjs/bodyparser/releases/tag/v10.1.5"},{"url":"https://github.com/adonisjs/bodyparser/releases/tag/v11.0.3"},{"url":"https://github.com/advisories/GHSA-qcm7-3vpr-hj5h"}],"tags":["ghsa","npm"],"ingestedAt":"2026-06-30T21:24:14.398Z","epss":0.00547,"epssPercentile":0.44706,"slug":"CVE-2026-48795","body":"## Overview\n\n### Summary\n\nThe fix for [GHSA-f5x2-vj4h-vg4c](https://github.com/adonisjs/core/security/advisories/GHSA-f5x2-vj4h-vg4c) / CVE-2026-25754 introduced in commit [`40e1c71`](https://github.com/adonisjs/bodyparser/commit/40e1c71f958cffb74f6b91bed6630dca979062ed) is incomplete and can be bypassed through nested prototype pollution payloads.\n\nThe original patch replaced the internal `FormFields` storage object with `Object.create(null)`, preventing direct payloads such as `__proto__.polluted`. However, payloads containing a non-dangerous segment before `__proto__` or `constructor.prototype`, such as `user.__proto__.polluted`, still lead to `Object.prototype` pollution.\n\nThis issue is exploitable remotely through a single unauthenticated `multipart/form-data` request using the default configuration.\n\n### Affected versions\n\n- `>= 10.1.3 < 10.1.5`\n- `>= 11.0.0-next.9 < 11.0.3`\n\n### Details\n\nThe regression tests added by the original fix only covered direct payloads such as:\n\n- `__proto__.polluted`\n- `constructor.prototype.polluted`\n\nThese payloads are blocked because the root object no longer inherits from `Object.prototype`.\n\nHowever, lodash `_.set()` (via `@poppinss/utils`) still creates intermediate objects using plain `{}` values. Once a normal segment is encountered, subsequent `__proto__` or `constructor.prototype` segments regain access to `Object.prototype`.\n\n### Impact\n\nAn unauthenticated attacker can remotely pollute `Object.prototype` on any route accepting multipart/form-data requests behind `BodyParserMiddleware`.\n\nBecause the pollution is process-wide, the impact may include authorization bypasses, unexpected behavior in downstream libraries, or prototype pollution gadget chains leading to remote code execution.\n\n### Patches\n\nFixes targeting v6 and v7 have been published below.\n\nUsers should upgrade to a version that includes the following fix:\n\n- https://github.com/adonisjs/bodyparser/releases/tag/v10.1.5\n- https://github.com/adonisjs/bodyparser/releases/tag/v11.0.3\n\n### References\n\n- [CWE-1321](https://cwe.mitre.org/data/definitions/1321.html)\n- Prior advisory this bypasses: [GHSA-f5x2-vj4h-vg4c](https://github.com/adonisjs/core/security/advisories/GHSA-f5x2-vj4h-vg4c) / CVE-2026-25754\n\n## Affected packages\n\n- `@adonisjs/bodyparser >= 10.1.3, <= 10.1.4`\n- `@adonisjs/bodyparser >= 11.0.0-next.9, <= 11.0.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `@adonisjs/bodyparser 10.1.5`\n- `@adonisjs/bodyparser 11.0.3`","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":47.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}