TopVuln

High-risk vulnerability digests

CVE-2026-39408

  • MEDIUM

MINI-GMQ3-6V89-CC2J

Details

CVSS v3
7.5
CVSS v4
5.9
NVD published
2026-04-08 15:16:14
EPSS
<0.1% probability · 1.6th percentile — 2026-04-28
Affected versions
cpe:2.3:a:hono:hono:*:*:*:*:*:node.js:*:*
Summary
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.12, a path traversal issue in toSSG() allows files to be written outside the configured output directory during static site generation. When using dynamic route parameters via ssgParams, specially crafted values can cause generated file paths to escape the intended output directory. This vulnerability is fixed in 4.12.12.
Remediation
Not available in our cache.
Exploit info
https://github.com/honojs/hono/security/advisories/GHSA-xf4j-xp2r-rqqx

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.