Critical AdonisJS Vulnerability Enables Remote Arbitrary File Write

TL;DR
A critical security flaw (CVSS 9.2) in the '@adonisjs/bodyparser' npm package allows remote attackers to perform arbitrary file writes on servers through path traversal in multipart file handling, emphasizing the need for immediate updates to affected versions. Additionally, a similar high-severity vulnerability was found in the jsPDF library, which has been patched in version 4.0.0.
- Critical AdonisJS Bodyparser Flaw (CVSS 9.2) Enables Arbitrary File Write on Servers The Hacker News
- Critical AdonisJS Vulnerability Allows Remote Attackers to Write Files on Servers Cyber Press
- Critical AdonisJS Vulnerability Allows Remote Attackers to Write Files on Server gbhackers.com
- Critical AdonisJS Vulnerability Allow Remote Attacker to Write Files On Server CybersecurityNews
Want the full story? Read the original reporting
Read on The Hacker News