What is CVE-2026-61526?
A critical vulnerability has been discovered in the AdonisJS HTTP Server (CVE-2026-61526). In versions 8.0.0-next.0 through 8.2.0 and 9.0.0 through 9.0.2, the error message is interpolated into the default HTML exception response without escaping, allowing a crafted missing-route URL to execute an XSS attack. Immediate upgrade to a patched version is recommended.
Azərbaycanca: AdonisJS HTTP Server paketində kritik boşluq aşkar edilib (CVE-2026-61526). 8.0.0-next.0-8.2.0 və 9.0.0-9.0.2 versiyalarında səhv mesajı (`error.message`) default HTML exception response-da düzgün escapelənmir, bu da xüsusi hazırlanmış URL vasitəsilə XSS hücumuna şərait yaradır. Ən qısa zamanda yeni versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
What functionality does CVE-2026-61526 affect in AdonisJS?
This vulnerability is related to the default HTML exception response in the AdonisJS HTTP Server where the `error.message` content is not properly escaped.
Which versions of AdonisJS are affected by CVE-2026-61526?
Versions 8.0.0-next.0 through 8.2.0 and versions 9.0.0 through 9.0.2 are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.