mediumCVSS 4.8Vulnerability

GHSA-v8w9-8mx6-g223

## Summary When using `parseBody({ dot: true })` in HonoRequest, specially crafted form field names such as `__proto__.x` could create objects containing a `__proto__` property. If the parsed result is later merged into regular JavaScript objects using unsafe merge patterns, this may lead to prototype pollution in the target object. ## Details The `parseBody({ dot: true })` feature supports dot notation to construct nested objects from form field names. In previous versions, the `__proto__` path segment was not filtered. As a result, specially crafted keys such as `__proto__.x` could produce objects containing `__proto__` properties. While this behavior does not directly modify `Object.prototype` within Hono itself, it may become exploitable if the parsed result is later merged into regular JavaScript objects using unsafe merge patterns. ## Impact Applications that merge parsed form data into regular objects using unsafe patterns (for example recursive deep merge utilities) may become vulnerable to prototype pollution.

Properties

ghsa_id
GHSA-v8w9-8mx6-g223
severity
medium
summary
Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })
cvss_score
4.8
cve_id
GHSA-v8w9-8mx6-g223
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
is_ghsa_only
true
ghsa_published
2026-03-11T00:31:47Z
source_url
https://github.com/advisories/GHSA-v8w9-8mx6-g223
ghsa_updated
2026-03-11T00:31:49Z

Related Entities (3)

AFFECTS (1)

[Software]npm/hono

HAS_WEAKNESS (1)

[Weakness]Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-v8w9-8mx6-g223 (CVSS 4.8) — Ninja Signal Threat Intelligence | Ninja Signal