The Lab · 2026-04-08 05:27:02 · GitHub Issues
A critical security vulnerability in the popular Hono.js web framework allows attackers to write files outside the intended directory during static site generation, posing a severe risk of arbitrary file creation and potential server compromise. The flaw, tracked as CVE-2026-39408, resides in the `toSSG()` function and...
The Lab · 2026-04-08 05:27:04 · GitHub Issues
A critical security flaw in the popular Hono.js web framework's static site generation feature has been disclosed, posing a direct risk of arbitrary file writes on affected systems. The vulnerability, tracked as CVE-2026-39408, resides within the `toSSG()` function. It allows an attacker to craft malicious dynamic rout...
The Lab · 2026-04-08 10:27:02 · GitHub Issues
A critical path traversal vulnerability has been disclosed in the popular Hono.js web framework, exposing projects using its static site generation (SSG) feature to potential file system compromise. The flaw, tracked as CVE-2026-39408, resides within the `toSSG()` function. When developers use dynamic route parameters ...
The Lab · 2026-04-19 07:22:29 · GitHub Issues
A critical path traversal vulnerability has been disclosed in the popular Hono.js web framework, exposing projects using its static site generation feature to potential file system compromise. The flaw, tracked as CVE-2026-39408, resides within the `toSSG()` function. It allows an attacker to write files outside the co...