# CVE-2026-22814

## Summary

- **CVE ID:** CVE-2026-22814
- **Severity:** HIGH
- **CVSS Score:** 8.2 (CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N)
- **CWE:** CWE-915
- **Published:** Jan 13, 2026
- **Last Modified:** Mar 12, 2026

## Description

@adonisjs/lucid is an SQL ORM for AdonisJS built on top of Knex. Prior to 21.8.2 and 22.0.0-next.6, there is a Mass Assignment vulnerability in AdonisJS Lucid which may allow a remote attacker who can influence data that is passed into Lucid model assignments to overwrite the internal ORM state. This may lead to logic bypasses and unauthorized record modification within a table or model. This affects @adonisjs/lucid through version 21.8.1 and 22.x pre-release versions prior to 22.0.0-next.6. This has been patched in @adonisjs/lucid versions 21.8.2 and 22.0.0-next.6.

## Affected Products

- adonisjs — lucid (< 21.8.2)
- adonisjs — lucid (>= 22.0.0-next.0, < 22.0.0-next.6)

## References

- [CNA](https://github.com/adonisjs/lucid/security/advisories/GHSA-g5gc-h5hp-555f)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.50%
- **EPSS Percentile:** 41.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._