Skip to content

[Security] @hono/node-server — ADVISORY #283

Description

@bitskc

Vulnerability Found

Package: @hono/node-server
Severity: moderate
Advisory: Node.js Adapter for Hono: Path traversal in serve-static on Windows via encoded backslash (%5C)
CVE: ADVISORY
CVSS Score: 5.9
CWE: CWE-22
Vulnerable Range: <1.19.15
Advisory URL: GHSA-frvp-7c67-39w9

Fix Recommendation

Update @hono/node-server to version yes or higher.

Detection

This vulnerability was detected by automated dependency scanning (npm audit).


This issue was automatically created by a dependency vulnerability scan.

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions