Description
Arbitrary code execution from cookie config. If dynamic cookies are enabled (ie there exists a schema for cookies), the cookie config is injected into the compiled route without first being sanitised.
Recommendation
Update the elysia package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.4.18
- Patched version(s): 1.4.18
References
Related Issues
- Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events - CVE-2025-64496
- protobuf.js: Code injection through bytes field defaults in generated toObject code - CVE-2026-44293
- Flowise is vulnerable to arbitrary file write through its WriteFileTool - CVE-2025-61913
- Lightning Flow Scanner Vulnerable to Code Injection via Unsafe Use of `new Function()` in APIVersion Rule - CVE-2025-67750
You might also like:
- Tags:
- npm
- elysia
Anything's wrong? Let us know Last updated on December 09, 2025


