OVERVIEW CVE-2026-39408 is a path traversal vulnerability in Hono, a JavaScript web application framework supporting multiple runtimes. The vulnerability exists in the toSSG() function used during static site generation, where specially crafted dynamic route parameters can cause generated files to be written outside the configured output directory, affecting versions prior to 4.12.12. SEVERITY This vulnerability carries a CVSS 3.1 score of 7.5 HIGH with a network-based attack vector that requires no authentication or user interaction. The attack has low complexity, making it relatively straightforward to exploit. The primary impact is a confidentiality breach, as attackers could read sensitive files outside the intended directory, though integrity and availability are not directly compromised. The FAUCET Risk Score of 48.0 indicates moderate overall risk. EXPLOITATION STATUS There is no evidence of active exploitation in the wild. The vulnerability does not currently appear on the Known Exploited Vulnerabilities (KEV) catalog, and it is not listed on the Hot List of actively exploited CVEs. However, given the network-accessible nature and low attack complexity, organizations running affected Hono versions should prioritize patching to version 4.12.12 or later as a precautionary measure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.0.0, <= 4.12.11CPE matchmatch criteria | cpe:2.3:a:hono:hono:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.