CVE-2026-21440 | adonisjs core up to 10.1.1 Multipart File path traversal (GHSA-gvq6-hvvp-h34h)
A vulnerability classified as critical has been found in adonisjs core up to 10.1.1. This affects an unknown part of the component Multipart File Handler. Performing a manipulation results in path traversal.
This vulnerability is cataloged as CVE-2026-21440. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.