GHSA-v8w9-8mx6-g223
## Summary When using `parseBody({ dot: true })` in HonoRequest, specially crafted form field names such as `__proto__.x` could create objects containing a `__proto__` property. If the parsed result is later merged into regular JavaScript objects using unsafe merge patterns, this may lead to prototype pollution in the target object. ## Details The `parseBody({ dot: true })` feature supports dot notation to construct nested objects from form field names. In previous versions, the `__proto__` path segment was not filtered. As a result, specially crafted keys such as `__proto__.x` could produce objects containing `__proto__` properties. While this behavior does not directly modify `Object.prototype` within Hono itself, it may become exploitable if the parsed result is later merged into regular JavaScript objects using unsafe merge patterns. ## Impact Applications that merge parsed form data into regular objects using unsafe patterns (for example recursive deep merge utilities) may become vulnerable to prototype pollution.
Properties
- ghsa_id
- GHSA-v8w9-8mx6-g223
- severity
- medium
- summary
- Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })
- cvss_score
- 4.8
- cve_id
- GHSA-v8w9-8mx6-g223
- cvss_vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
- is_ghsa_only
- true
- ghsa_published
- 2026-03-11T00:31:47Z
- source_url
- https://github.com/advisories/GHSA-v8w9-8mx6-g223
- ghsa_updated
- 2026-03-11T00:31:49Z
Related Entities (3)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph