THREAT OPS › Threat News › [GHSA] GHSA-gqvv-2mrq-wpjv (medium) — Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory
[GHSA] GHSA-gqvv-2mrq-wpjv (medium) — Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory
GHSA-gqvv-2mrq-wpjv Severity: medium CVE: CVE-2026-84365
Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory
### Summary
The fix released for CVE-2026-39408 does not cover every traversal sequence. `toSSG()` can still write files outside the configured output directory when a route parameter contains consecutive parent-directory segments.
### Deta
Indicators of compromise
- CVE-2026-39408cve
- CVE-2026-84365cve
Original source: https://github.com/advisories/GHSA-gqvv-2mrq-wpjv