npm @hono/node-server 2.1.3

2 hours ago

Security fixes

serveStatic decodes the request path a second time, leading to bypass of middleware on static paths

Affects: @hono/node-server/serve-static. Fixes serveStatic decoding an already-decoded path, where a crafted request could be routed as one path and served as another, skipping middleware mounted on a static prefix. GHSA-rmxm-3fg6-px4f

serveStatic now rejects request paths that still contain % after decoding. To serve files whose names contain a literal %, set allowPercentInPath: true.

The same fix ships in hono v4.13.11.

Don't miss a new node-server release

NewReleases is sending notifications on new releases.