hono is vulnerable to Path Traversal
65
Medium Risk
Hono's toSSG() static site generator normalizes route parameter values before writing output files, but the normalization does not fully collapse consecutive parent-directory segments supplied through ssgParams. Crafted route parameter values can therefore escape the configured output directory and write generated files to arbitrary locations on disk. This is an incomplete fix for an earlier path traversal in the same function that remained exploitable through chained ../ segments. The patch strengthens containment so generated paths stay within the configured output directory.
You are affected if you are using a version that falls within the vulnerable range and you use toSSG() for static site generation with ssgParams route parameter values derived from untrusted input.
hono is vulnerable to Path Traversal in versions 0.0.1 - 4.13.4.
Upgrade the hono library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.