Description
Arbitrary code execution from cookie config. If dynamic cookies are enabled (ie there exists a schema for cookies), the cookie config is injected into the compiled route without first being sanitised.
Recommendation
Update the elysia package to the latest compatible version. Followings are version details:
- Affected version(s): < 1.4.18
- Patched version(s): 1.4.18
References
Could your website be exposed too?
SmartScanner can check your website for Elysia affected by arbitrary code injection through cookie config and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Open WebUI Affected by an External Model Server (Direct Connections) Code Injection via SSE Events - CVE-2025-64496
- protobuf.js: Code injection through bytes field defaults in generated toObject code - CVE-2026-44293
- Flowise is vulnerable to arbitrary file write through its WriteFileTool - CVE-2025-61913
- Lightning Flow Scanner Vulnerable to Code Injection via Unsafe Use of `new Function()` in APIVersion Rule - CVE-2025-67750


