VDB
Sign up
MEDIUM5.3

GHSA-rjq5-w47x-x359

@hono/node-server cannot handle "double dots" in URL

Quick fix

GHSA-rjq5-w47x-x359 — @hono/node-server: upgrade to the fixed version with the command below.

npm install @hono/node-server@1.4.1

Details

### Impact

Since v1.3.0, we use our own Request object. This is great, but the `url` behavior is unexpected.

In the standard API, if the URL contains `..`, here called "double dots", the URL string returned by Request will be in the resolved path.

```ts const req = new Request('http://localhost/static/../foo.txt') // Web-standards console.log(req.url) // http://localhost/foo.txt ```

However, the `url` in our Request does not resolve double dots, so `http://localhost/static/.. /foo.txt` is returned.

```ts const req = new Request('http://localhost/static/../foo.txt') console.log(req.url) // http://localhost/static/../foo.txt ```

It will pass unresolved paths to the web application. This causes vulnerabilities like #123 when using `serveStatic`.

Note: Modern web browsers and a latest `curl` command resolve double dots on the client side, so it does not affect you if the user uses them. However, problems may occur if accessed by a client that does not resolve them.

### Patches

"v1.4.1" includes the change to fix this issue.

### Workarounds

Don't use `serveStatic`.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@hono/node-server
Introduced in: 1.3.0Fixed in: 1.4.1
Fixnpm install @hono/node-server@1.4.1

References