{"id":"CVE-2026-22814","summary":"Mass Assignment in AdonisJS Lucid Allows Overwriting Internal ORM State","details":"@adonisjs/lucid is an SQL ORM for AdonisJS built on top of Knex. Prior to 21.8.2 and 22.0.0-next.6, there is a Mass Assignment vulnerability in AdonisJS Lucid which may allow a remote attacker who can influence data that is passed into Lucid model assignments to overwrite the internal ORM state. This may lead to logic bypasses and unauthorized record modification within a table or model. This affects @adonisjs/lucid through version 21.8.1 and 22.x pre-release versions prior to 22.0.0-next.6. This has been patched in @adonisjs/lucid versions 21.8.2 and 22.0.0-next.6.","aliases":["GHSA-g5gc-h5hp-555f"],"modified":"2026-08-12T03:51:21.961533840Z","published":"2026-01-13T19:42:14.346Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22814.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-915"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22814.json"},{"type":"ADVISORY","url":"https://github.com/adonisjs/lucid/security/advisories/GHSA-g5gc-h5hp-555f"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22814"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/adonisjs/lucid","events":[{"introduced":"0"},{"fixed":"ac24b2acb1ed97afaae09d738441f6ab90ab6dca"},{"introduced":"41f98120379da0033d57038abff10a3ee4d7b783"},{"fixed":"72eff799ec1173dee35c2bb9713fb2bc12b521fd"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"21.8.2"},{"introduced":"22.0.0-next.0"},{"fixed":"22.0.0-next.6"}]}}],"versions":["v22.0.0-next.5","v21.8.1","v22.0.0-next.4","v22.0.0-next.3","v22.0.0-next.2","v22.0.0-next.1","v22.0.0-next.0","v21.8.0","v21.7.0","v21.6.1","v21.6.0","v21.5.1","v21.5.0","v21.4.0","v21.3.0","v21.2.0","v21.1.1","v21.1.0","v21.0.1","v21.0.0","v20.6.0","v20.0.0","v20.5.1","v20.4.0","v20.3.0","v20.2.0","v20.1.0","v19.0.0","v18.4.1","v18.4.0","v18.3.0","v18.2.0","v18.1.1","v18.1.0","v18.0.1","v18.0.0","v17.2.0","v17.1.1","v17.1.0","v17.0.1","v17.0.0","v16.3.2","v16.3.1","v16.3.0","v16.2.2","v16.2.1","v16.2.0","v16.1.0","v16.0.2","v16.0.1","v16.0.0","v15.0.3","v15.0.2","v15.0.1","v15.0.0","v14.2.0","v14.1.0","v14.0.2","v14.0.1","v14.0.0","v13.0.0","v12.0.0","v11.0.1","v11.0.0","v10.0.0","v9.0.3","v9.0.2","v9.0.1","v9.0.0","v8.5.0","v8.4.4","v8.4.3","v8.4.2","v8.4.1","v8.4.0","v8.3.1","v8.2.2","v8.2.1","v8.2.0","v8.1.1","v8.1.0","v8.0.5","v8.0.4","v8.0.3","v8.0.2","v8.0.1","v8.0.0","v7.6.3","v7.6.2","v7.6.1","v7.6.0","v7.5.5","v7.5.4","v7.5.3","v7.5.2","v7.5.1","v7.5.0","v7.4.3","v7.4.2","v7.4.1","v7.4.0","v7.3.1","v7.3.0","v7.2.1-0","v7.2.1","v7.2.0-0","v7.1.6-0","v7.1.5-0","v7.1.4-0","v7.1.3-0","v7.1.2-0","v7.1.1-0","v7.1.0-0","v7.0.1-0","v7.0.0-0","v6.1.3","v6.1.2","v6.1.1","v6.1.0","v6.0.1","v6.0.0","v5.0.4","v5.0.3","v5.0.2","v5.0.1","v5.0.0","v4.1.3","v4.1.2","v4.1.1","v4.1.0","v4.0.25","v4.0.24","v4.0.23","v4.0.22","v4.0.21","v4.0.20","v4.0.19","v4.0.18","v4.0.17","v4.0.16","v4.0.15","v4.0.14","v4.0.13","v4.0.12","v4.0.11","v4.0.10","v4.0.9","v4.0.8","v4.0.7","v4.0.6","v4.0.5","v4.0.4","v4.0.3","v4.0.2","v4.0.1","v4.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22814.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N"}]}