CVE-2024-32869

MEDIUM

Hono < 4.2.7 - Path Traversal

Title source: rule
STIX 2.1

Description

Hono is a Web application framework that provides support for any JavaScript runtime. Prior to version 4.2.7, when using serveStatic with deno, it is possible to traverse the directory where `main.ts` is located. This can result in retrieval of unexpected files. Version 4.2.7 contains a patch for the issue.

Scores

CVSS v3 5.3
EPSS 0.0128
EPSS Percentile 79.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
hono/hono < 4.2.7
npm/hono 0 - 4.2.7npm
Published Apr 23, 2024
Tracked Since Feb 18, 2026