@hono/node-server is vulnerable to Authentication Bypass
53
Medium Risk
serveStatic decodes the routed request path a second time before resolving a file, after Hono's router has already decoded it once. A request with a malformed or double percent encoded path can route against one path while serveStatic resolves and serves a different file under the same root, so middleware mounted on a narrower prefix, such as an authentication check, does not run for that file. The resolved file still stays inside the configured root, so this is a middleware bypass rather than directory traversal. The patch adds an allowPercentInPath option and rejects routed paths containing % by default before decoding.
You are affected if you are using a version that falls within the vulnerable range and you mount middleware, such as an authentication check, on a path narrower than the one served by serveStatic.
@hono/node-server is vulnerable to Authentication Bypass in versions 0.0.1 - 2.1.2.
Upgrade the @hono/node-server library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.