Skip to content

[Security] @hono/node-server — ADVISORY #281

Description

@bitskc

Vulnerability Found

Package: @hono/node-server
Severity: high
Advisory: @hono/node-server has authorization bypass for protected static paths via encoded slashes in Serve Static Middleware
CVE: ADVISORY
CVSS Score: 7.5
CWE: CWE-863
Vulnerable Range: <1.19.10
Advisory URL: GHSA-wc8c-qw6v-h7f6

Fix Recommendation

Update @hono/node-server to version yes or higher.

Detection

This vulnerability was detected by automated dependency scanning (npm audit).


This issue was automatically created by a dependency vulnerability scan.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions