CVE-2026-84365: Hono: Incomplete fix for CVE-2026-39408: `toSSG()` still writes files outside the output directory
The fix released for CVE-2026-39408 does not cover every traversal sequence. toSSG() can still write files outside the configured output directory when a route parameter contains consecutive parent-directory segments.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-84365 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →