Description
hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside an asynchronous sibling, as the single child of a Context.Provider, or as the root value passed to renderToString() or renderToReadableStream() from hono/jsx/dom/server. These paths stringify their input and treat the result as already-escaped markup, so an attacker who controls such a string during server-side rendering can inject arbitrary HTML and execute script under the application's origin.
Published: 2026-09-19
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Client‑side script execution via XSS during server‑side rendering
Action: Apply Update
AI Analysis

Impact

Hono applications using the hono/jsx library before version 4.13.7 are vulnerable because plain strings that are passed as children, fallbacks, or root values are rendered without HTML escaping. The library stringifies these inputs and treats the result as already escaped markup. An attacker who can provide such a string during server‑side rendering can inject arbitrary HTML and execute JavaScript in the application’s origin, leading to data theft, session hijacking, or defacement. The vulnerability is a classic stored client‑side XSS (CWE‑79).

Affected Systems

The affected software is Hono, the web framework from honojs. All releases prior to 4.13.7 are impacted; versions 4.13.7 and later address the issue.

Risk and Exploitability

The CVSS score for this vulnerability is 2.3, indicating low severity. EPSS data is not available and the flaw is not listed in the CISA KEV catalog. Exploitation requires an attacker to inject a controlled string that is subsequently rendered by the library during server‑side rendering; it is not a remote network exploit. While the technical impact is limited to the client side, the potential for data compromise and phishing makes it important to address promptly.

Generated by OpenCVE AI on September 19, 2026 at 23:36 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Hono to version 4.13.7 or later.
  • If an immediate upgrade is not possible, ensure that any user‑controlled strings passed to hono/jsx are properly escaped or sanitized before rendering.
  • Audit server‑side rendering code to verify that no unescaped strings are provided as children to Suspense fallbacks, ErrorBoundary children, Context.Provider children, or as the root value to renderToString() or renderToReadableStream().

Generated by OpenCVE AI on September 19, 2026 at 23:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-hxh3-vqpv-xpqv hono/jsx renders plain strings unescaped in boundary components, leading to XSS
History

Wed, 23 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Mon, 21 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Description hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside an asynchronous sibling, as the single child of a Context.Provider, or as the root value passed to renderToString() or renderToReadableStream() from hono/jsx/dom/server. These paths stringify their input and treat the result as already-escaped markup, so an attacker who controls such a string during server-side rendering can inject arbitrary HTML and execute script under the application's origin.
Title hono/jsx before 4.13.7 Cross-Site Scripting via Unescaped Strings
First Time appeared Hono
Hono hono
Weaknesses CWE-79
CPEs cpe:2.3:a:hono:hono:*:*:*:*:*:*:*:*
Vendors & Products Hono
Hono hono
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T20:47:06.182Z

Reserved: 2026-09-19T10:55:49.092Z

Link: CVE-2026-93981

cve-icon Vulnrichment

Updated: 2026-09-21T16:22:57.390Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T12:16:41.080

Modified: 2026-09-21T21:17:20.740

Link: CVE-2026-93981

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-19T11:53:34Z

Links: CVE-2026-93981 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T03:00:10Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')