THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-gqvv-2mrq-wpjv (medium) — Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory

[GHSA] GHSA-gqvv-2mrq-wpjv (medium) — Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory

medgithub_advisoriesPublished 2026-09-08

GHSA-gqvv-2mrq-wpjv Severity: medium CVE: CVE-2026-84365

Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory

### Summary

The fix released for CVE-2026-39408 does not cover every traversal sequence. `toSSG()` can still write files outside the configured output directory when a route parameter contains consecutive parent-directory segments.

### Deta

Indicators of compromise

Original source: https://github.com/advisories/GHSA-gqvv-2mrq-wpjv