Intel

AIKIDO-2026-999858

@hono/node-server is vulnerable to Authentication Bypass

Authentication BypassGHSA-rmxm-3fg6-px4f Published 2 days ago

53

Medium Risk

This Affects:

JS@hono/node-server
0.0.1 - 2.1.2
Fixed in 2.1.3
Are you affected? Scan for Free

TL;DR

serveStatic decodes the routed request path a second time before resolving a file, after Hono's router has already decoded it once. A request with a malformed or double percent encoded path can route against one path while serveStatic resolves and serves a different file under the same root, so middleware mounted on a narrower prefix, such as an authentication check, does not run for that file. The resolved file still stays inside the configured root, so this is a middleware bypass rather than directory traversal. The patch adds an allowPercentInPath option and rejects routed paths containing % by default before decoding.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and you mount middleware, such as an authentication check, on a path narrower than the one served by serveStatic.

Background info

@hono/node-server is vulnerable to Authentication Bypass in versions 0.0.1 - 2.1.2.

How to fix this

Upgrade the @hono/node-server library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform