CVE-2026-21440 is a path traversal vulnerability in the multipart file-handling functionality of the AdonisJS @adonisjs/bodyparser package. MultipartFile.move() can use an unsanitized client-supplied filename as part of the destination path, allowing a remote attacker to write files outside the intended upload directory. The issue affects versions through 10.1.1 and 11.x prerelease versions before 11.0.0-next.6.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a single Python exploit script and a README describing CVE-2026-21440 (path traversal leading to arbitrary file write) in AdonisJS @adonisjs/bodyparser multipart upload handling. Structure: - CVE-2026-21440.py: Standalone Python3 PoC/exploit using requests + argparse. - README.md: Vulnerability overview, affected versions, remediation guidance, and example usage. Exploit behavior/capabilities (CVE-2026-21440): - Sends a multipart/form-data POST to a user-supplied upload endpoint URL. - Abuses the multipart filename parameter by prepending traversal sequences ("../" * depth) or using a user-supplied absolute path to attempt writing outside the intended upload directory. - Supports randomizing the base filename to avoid collisions. - Payload options: - Safe mode: writes a harmless .txt marker to confirm arbitrary write. - Webshell presets: writes minimal PHP/JSP/ASPX command-execution stubs (expects a 'cmd' parameter). - Custom content: arbitrary attacker-provided file content. - Operational features: custom headers (including Cookie/Authorization), extra form fields, proxy support, optional TLS verification disable, and verbose output on failure. Targeting assumptions: - The target endpoint must accept a multipart file field named 'file'. - Successful RCE depends on writing into a web-accessible and executable location for the chosen server stack (PHP/JSP/ASPX). Otherwise, the exploit still provides arbitrary file write within the server process permissions. No evidence of being part of a larger exploit framework; it is a direct, single-script network exploit.
Repository contains a single Python exploit script and a README. - Files: - CVE-2026-21440-code.py: Standalone Python tool using requests + argparse. - README.md: Chinese usage guide, parameter table, and disclaimer. - Purpose/flow: 1) Verification mode (default): constructs a URL by concatenating the base target URL with a Windows file path (slashes normalized) and performs an HTTP GET. If HTTP 200 and non-empty body, it reports the target as vulnerable and prints the retrieved file contents. Includes preset sensitive Windows paths (win.ini, hosts, system.ini, SAM, Security hive, init.ini) and supports a custom path. 2) Exploit mode (--exploit): performs an HTTP PUT to write a webshell to an operator-specified filesystem path (intended to be within the web root, e.g., C:/phpstudy/WWW/shell.php). It then GETs the shell URL to confirm it is accessible, and finally POSTs to the shell with a parameter named by --pass (default cve2026) to execute a test command (default whoami). Supports PHP and ASP shell variants. - Notable implementation details: - Disables TLS certificate verification (verify=False) and suppresses urllib3 warnings. - Uses allow_redirects=False for the initial GET/PUT, and basic timeout handling. - RCE is achieved via a classic eval-based webshell; command execution is attempted by sending code in the POST body. Overall, this is an operational exploit (not just detection): it combines arbitrary file read verification with an arbitrary file write (PUT) leading to webshell-based remote command execution on Windows web servers that map URL paths to filesystem paths and permit PUT uploads.
This repository provides a comprehensive proof-of-concept (PoC) exploit for CVE-2026-21440, a critical path traversal vulnerability in the @adonisjs/bodyparser package (Node.js). The exploit allows remote attackers to write arbitrary files outside the intended upload directory by submitting a crafted filename containing directory traversal sequences (e.g., '../../etc/passwd') in a multipart/form-data upload. The main exploit is implemented in Python (Exploit-PoC/exploit.py), which constructs and sends a raw HTTP POST request to the vulnerable upload endpoint, bypassing filename sanitization and leveraging the vulnerability to write files to attacker-specified locations. The payload can be arbitrary content, including webshells or cron jobs, and is fully user-controlled via command-line arguments. The repository also includes a vulnerable Node.js/Express application (Vulnerable-App/server.ts) that simulates the affected AdonisJS behavior for testing purposes. The exploit is network-based, targeting HTTP endpoints, and is effective against any application using the vulnerable @adonisjs/bodyparser versions with insecure file upload handling. The repository is well-documented, with clear usage instructions, mitigation guidance, and a detailed technical breakdown of the vulnerability and its exploitation.
This repository provides a comprehensive proof-of-concept (PoC) exploit for CVE-2026-21440, a critical path traversal vulnerability in the @adonisjs/bodyparser package for Node.js. The vulnerability allows remote attackers to write arbitrary files outside the intended upload directory by supplying crafted filenames containing directory traversal sequences (e.g., '../../etc/passwd') to a vulnerable file upload endpoint. The repository is structured into two main components: - **Exploit-PoC/**: Contains the main exploit script (`exploit.py`), a requirements file, and documentation. The Python script allows the user to specify a target upload endpoint, a traversal path for the file write, and the content or payload to write. It crafts a raw HTTP multipart request with a malicious filename and sends it directly to the target, bypassing client-side sanitization. The script supports custom payloads, webshells, and can check target health. - **Vulnerable-App/**: Provides a minimal, intentionally vulnerable Node.js/Express application (`server.ts`) that mimics the vulnerable behavior of @adonisjs/bodyparser. The upload endpoint (`POST /upload`) uses the client-supplied filename without sanitization, allowing path traversal. The app also exposes `/health` and `/` endpoints for status and info. The exploit is operational and demonstrates arbitrary file write, which can be leveraged for remote code execution, configuration overwrite, or other post-exploitation actions. The repository includes detailed documentation, usage instructions, and a Dockerfile for setting up a test environment. No fake or malicious code is present; the exploit is a legitimate PoC for security research and testing.
This repository contains a single Python proof-of-concept exploit (CVE-2026-21440.py) and a detailed README.md. The exploit targets a critical path traversal vulnerability (CVE-2026-21440) in the AdonisJS @adonisjs/bodyparser package, allowing attackers to write arbitrary files to the server by abusing unsanitized filenames in multipart file uploads. The exploit script is highly configurable: it supports custom traversal depth, random filenames, uploading various types of webshells (PHP, JSP, ASPX), custom file content, and additional HTTP headers/cookies. It can also operate through a proxy and has a safe mode for non-destructive testing. The README provides comprehensive background, usage instructions, and remediation advice. The main attack vector is a network-accessible file upload endpoint, and the exploit can lead to remote code execution if a webshell is uploaded. The repository is well-structured, with clear separation between exploit code and documentation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
27 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A path traversal vulnerability in AdonisJS BodyParser that could enable arbitrary file access and/or other arbitrary actions (exact impact truncated in the provided content).
AdonisJS bodyparser path traversal enabling arbitrary file write on servers.
Critical path traversal issue in @adonisjs/bodyparser (multipart handling) enabling arbitrary file write on servers.
Critical path traversal vulnerability in the NPM package @adonisjs/bodyparser. In multipart file handling via MultipartFile.move(), if the name parameter is not provided, the application uses an unsanitized client-supplied filename, allowing a remote unauthenticated attacker to write arbitrary files to arbitrary locations on the server filesystem, including overwriting existing files.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.