Skip to content

chore: upgrade hono to 4.13.7 to address CVE-2026-84363, CVE-2026-84364, CVE-2026-84365 - #1643

Merged
brendan-kellam merged 6 commits into
mainfrom
cursor/cve/hono
Sep 10, 2026
Merged

chore: upgrade hono to 4.13.7 to address CVE-2026-84363, CVE-2026-84364, CVE-2026-84365#1643
brendan-kellam merged 6 commits into
mainfrom
cursor/cve/hono

Conversation

@claude

@claude claude Bot commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

Fixes SOU-2203
Fixes SOU-2204
Fixes SOU-2205

Refreshes the yarn.lock entry for hono from 4.13.0 to 4.13.7.

hono is a transitive dependency of @modelcontextprotocol/sdk (used by packages/web), requested at ^4.11.4. That range already admitted the patched release, so this is a lockfile refresh only. No package.json change and no resolutions override were needed.

Advisories addressed

All three are patched in 4.13.5:

Advisory Summary
CVE-2026-84363 Query parser reads parameters after the URL fragment, causing cache-key and proxy interpretation differentials
CVE-2026-84364 Unbounded dot-notation nesting in parseBody() can cause memory exhaustion
CVE-2026-84365 Incomplete fix for CVE-2026-39408: toSSG() still writes files outside the output directory

Verification

  • yarn why hono reports every instance resolving to hono@npm:4.13.7, with no vulnerable version remaining in the graph.
  • yarn workspace @sourcebot/web test --run — 140 files, 1440 tests passed.

🤖 Generated with Claude Code


Note

Low Risk
Lockfile-only dependency bump with no application code changes; risk is limited to transitive HTTP/MCP stack behavior in patched hono versions.

Overview
Bumps the resolved hono version from 4.13.0 to 4.13.7 in yarn.lock to address CVE-2026-84363, CVE-2026-84364, and CVE-2026-84365. hono is pulled in transitively by @modelcontextprotocol/sdk in packages/web (range ^4.11.4), so there is no package.json or resolutions change—only a lockfile refresh.

Documents the upgrade under Unreleased → Fixed in CHANGELOG.md.

Reviewed by Cursor Bugbot for commit 07cd3fa. Bugbot is set up for automated code reviews on this repo. Configure here.


Summary by cubic

Fixes SOU-2203, SOU-2204, and SOU-2205 by upgrading hono from 4.13.0 to 4.13.7 in yarn.lock to patch CVE-2026-84363, CVE-2026-84364, and CVE-2026-84365. hono is a transitive dependency of @modelcontextprotocol/sdk in packages/web, requested at ^4.11.4, so this is a lockfile-only refresh with no package.json change.

Verification

  • yarn why hono reports every instance resolving to hono@npm:4.13.7 with no vulnerable version remaining.
  • yarn workspace @sourcebot/web test --run passes (140 files, 1440 tests).
  • Adds a CHANGELOG.md entry under Unreleased → Fixed.

Written for commit 07cd3fa. Summary will update on new commits.

Review in cubic

claude Bot and others added 2 commits August 17, 2026 08:33
, CVE-2026-71850

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 10, 2026

Copy link
Copy Markdown
Contributor

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: eb3e0eb9-233d-44dc-a6f3-51b4813c4cfc

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Discards the abandoned hono ^4.13.2 work from closed PR #1597 in favour of a fresh refresh against current main.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes using high effort and found 1 potential issue.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Want reviews to match your repository better? Bugbot Learning can learn team-specific rules from PR activity. A team admin can enable Learning in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 40b45ca. Configure here.

Comment thread yarn.lock Outdated
github-actions Bot and others added 2 commits September 10, 2026 12:35
Refreshes the yarn.lock entry for hono from 4.13.0 to 4.13.7. hono is a
transitive dependency of @modelcontextprotocol/sdk, whose `^4.11.4` range
already admitted the patched version, so no manifest change or resolution
override is needed.

Addresses CVE-2026-84363, CVE-2026-84364 and CVE-2026-84365.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@claude
claude Bot requested a review from brendan-kellam September 10, 2026 12:36
@brendan-kellam
brendan-kellam merged commit 83ba5eb into main Sep 10, 2026
12 checks passed
@brendan-kellam
brendan-kellam deleted the cursor/cve/hono branch September 10, 2026 18:33
@github-actions

Copy link
Copy Markdown
Contributor

License Audit

⚠️ Status: PASS

Metric Count
Total packages 2174
Resolved (non-standard) 26
Unresolved 0
Strong copyleft 0
Weak copyleft 28

Weak Copyleft Packages (informational)

Package Version License
@img/sharp-libvips-darwin-arm64 1.3.3 LGPL-3.0-or-later
@img/sharp-libvips-darwin-x64 1.3.3 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm 1.3.3 LGPL-3.0-or-later
@img/sharp-libvips-linux-arm64 1.3.3 LGPL-3.0-or-later
@img/sharp-libvips-linux-ppc64 1.3.3 LGPL-3.0-or-later
@img/sharp-libvips-linux-riscv64 1.3.3 LGPL-3.0-or-later
@img/sharp-libvips-linux-s390x 1.3.3 LGPL-3.0-or-later
@img/sharp-libvips-linux-x64 1.3.3 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-arm64 1.3.3 LGPL-3.0-or-later
@img/sharp-libvips-linuxmusl-x64 1.3.3 LGPL-3.0-or-later
@img/sharp-wasm32 0.35.4 Apache-2.0 AND LGPL-3.0-or-later AND MIT
@img/sharp-win32-arm64 0.35.4 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-ia32 0.35.4 Apache-2.0 AND LGPL-3.0-or-later
@img/sharp-win32-x64 0.35.4 Apache-2.0 AND LGPL-3.0-or-later
axe-core 4.10.3 MPL-2.0
dompurify 3.4.13 (MPL-2.0 OR Apache-2.0)
lightningcss 1.32.0 MPL-2.0
lightningcss-android-arm64 1.32.0 MPL-2.0
lightningcss-darwin-arm64 1.32.0 MPL-2.0
lightningcss-darwin-x64 1.32.0 MPL-2.0
lightningcss-freebsd-x64 1.32.0 MPL-2.0
lightningcss-linux-arm-gnueabihf 1.32.0 MPL-2.0
lightningcss-linux-arm64-gnu 1.32.0 MPL-2.0
lightningcss-linux-arm64-musl 1.32.0 MPL-2.0
lightningcss-linux-x64-gnu 1.32.0 MPL-2.0
lightningcss-linux-x64-musl 1.32.0 MPL-2.0
lightningcss-win32-arm64-msvc 1.32.0 MPL-2.0
lightningcss-win32-x64-msvc 1.32.0 MPL-2.0
Resolved Packages (26)
Package Version Original Resolved Source
@sentry/cli 2.58.5 FSL-1.1-MIT FSL-1.1-MIT published package LICENSE file + GitHub repo (getsentry/sentry-cli); Functional Source License 1.1 (MIT Future License), not an SPDX-registered identifier
@sentry/cli 2.58.6 FSL-1.1-MIT FSL-1.1-MIT published package LICENSE file + GitHub repo (getsentry/sentry-cli); Functional Source License 1.1 (MIT Future License), not an SPDX-registered identifier
@sentry/cli-darwin 2.58.5 FSL-1.1-MIT FSL-1.1-MIT published package LICENSE file + GitHub repo (getsentry/sentry-cli); Functional Source License 1.1 (MIT Future License), not an SPDX-registered identifier
@sentry/cli-darwin 2.58.6 FSL-1.1-MIT FSL-1.1-MIT published package LICENSE file + GitHub repo (getsentry/sentry-cli); Functional Source License 1.1 (MIT Future License), not an SPDX-registered identifier
@sentry/cli-linux-arm 2.58.5 FSL-1.1-MIT FSL-1.1-MIT published package LICENSE file + GitHub repo (getsentry/sentry-cli); Functional Source License 1.1 (MIT Future License), not an SPDX-registered identifier
@sentry/cli-linux-arm 2.58.6 FSL-1.1-MIT FSL-1.1-MIT published package LICENSE file + GitHub repo (getsentry/sentry-cli); Functional Source License 1.1 (MIT Future License), not an SPDX-registered identifier
@sentry/cli-linux-arm64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT published package LICENSE file + GitHub repo (getsentry/sentry-cli); Functional Source License 1.1 (MIT Future License), not an SPDX-registered identifier
@sentry/cli-linux-arm64 2.58.6 FSL-1.1-MIT FSL-1.1-MIT published package LICENSE file + GitHub repo (getsentry/sentry-cli); Functional Source License 1.1 (MIT Future License), not an SPDX-registered identifier
@sentry/cli-linux-i686 2.58.5 FSL-1.1-MIT FSL-1.1-MIT published package LICENSE file + GitHub repo (getsentry/sentry-cli); Functional Source License 1.1 (MIT Future License), not an SPDX-registered identifier
@sentry/cli-linux-i686 2.58.6 FSL-1.1-MIT FSL-1.1-MIT published package LICENSE file + GitHub repo (getsentry/sentry-cli); Functional Source License 1.1 (MIT Future License), not an SPDX-registered identifier
@sentry/cli-linux-x64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT published package LICENSE file + GitHub repo (getsentry/sentry-cli); Functional Source License 1.1 (MIT Future License), not an SPDX-registered identifier
@sentry/cli-linux-x64 2.58.6 FSL-1.1-MIT FSL-1.1-MIT published package LICENSE file + GitHub repo (getsentry/sentry-cli); Functional Source License 1.1 (MIT Future License), not an SPDX-registered identifier
@sentry/cli-win32-arm64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT published package LICENSE file + GitHub repo (getsentry/sentry-cli); Functional Source License 1.1 (MIT Future License), not an SPDX-registered identifier
@sentry/cli-win32-arm64 2.58.6 FSL-1.1-MIT FSL-1.1-MIT published package LICENSE file + GitHub repo (getsentry/sentry-cli); Functional Source License 1.1 (MIT Future License), not an SPDX-registered identifier
@sentry/cli-win32-i686 2.58.5 FSL-1.1-MIT FSL-1.1-MIT published package LICENSE file + GitHub repo (getsentry/sentry-cli); Functional Source License 1.1 (MIT Future License), not an SPDX-registered identifier
@sentry/cli-win32-i686 2.58.6 FSL-1.1-MIT FSL-1.1-MIT published package LICENSE file + GitHub repo (getsentry/sentry-cli); Functional Source License 1.1 (MIT Future License), not an SPDX-registered identifier
@sentry/cli-win32-x64 2.58.5 FSL-1.1-MIT FSL-1.1-MIT published package LICENSE file + GitHub repo (getsentry/sentry-cli); Functional Source License 1.1 (MIT Future License), not an SPDX-registered identifier
@sentry/cli-win32-x64 2.58.6 FSL-1.1-MIT FSL-1.1-MIT published package LICENSE file + GitHub repo (getsentry/sentry-cli); Functional Source License 1.1 (MIT Future License), not an SPDX-registered identifier
codemirror-lang-elixir 4.0.0 UNKNOWN Apache-2.0 published package LICENSE file + GitHub repo (livebook-dev/codemirror-lang-elixir)
khroma 2.1.0 UNKNOWN MIT published package LICENSE file
lezer-elixir 1.1.2 UNKNOWN Apache-2.0 published package LICENSE file + GitHub repo (livebook-dev/lezer-elixir)
map-stream 0.1.0 UNKNOWN MIT published package LICENCE file
memorystream 0.3.1 UNKNOWN MIT extracted from object (legacy "licenses[0].type") + published package LICENSE file
pause-stream 0.0.11 ["MIT","Apache2"] (MIT OR Apache-2.0) extracted from object (license array ["MIT","Apache2"]) + published package LICENSE file ("Dual Licensed MIT and Apache 2")
posthog-js 1.369.0 SEE LICENSE IN LICENSE Apache-2.0 published package LICENSE file (Apache-2.0; some vendored files additionally MIT)
valid-url 1.0.9 UNKNOWN MIT published package LICENSE file

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant