Executive brief
AdonisJS Lucid is a database ORM library used by Node.js web applications to manage data and database operations. A mass assignment vulnerability allows attackers to inject arbitrary internal ORM properties into model creation or update operations, enabling them to bypass record modification restrictions, convert insert operations to updates, and circumvent application logic by directly manipulating the database persistence state.
Technical details
A mass assignment (CWE-915) vulnerability in the BaseModelImpl class of @adonisjs/lucid allows attackers to overwrite internal ORM state properties via model assignment methods (fill, merge, create, createMany, updateOrCreate, etc.). The vulnerability arises because the library validates property assignment using hasOwnProperty(key), which passes for internal instance properties like $isPersisted, $attributes, $original, and $isDeleted. An attacker who can influence the payload passed to model creation or update methods (e.g., via unvalidated request data) can inject these internal keys to hijack ORM logic—for example, setting $isPersisted: true forces an INSERT operation to become an UPDATE, or modifying $attributes bypasses validators. The attack requires network access and the ability to influence data passed to vulnerable model methods; applications using strict input allow lists that drop unknown properties are not affected. Patches are available in versions 21.8.2 and 22.0.0-next.6.
Affected products
- AdonisJS Lucid <= 21.8.1, 22.0.0-next.0 through 22.0.0-next.5
Timeline
- 2026-01-13: disclosed: Vulnerability published
- 2026-01-13: patched: Patches released in versions 21.8.2 and 22.0.0-next.6