Impact
Hono applications using the hono/jsx library before version 4.13.7 are vulnerable because plain strings that are passed as children, fallbacks, or root values are rendered without HTML escaping. The library stringifies these inputs and treats the result as already escaped markup. An attacker who can provide such a string during server‑side rendering can inject arbitrary HTML and execute JavaScript in the application’s origin, leading to data theft, session hijacking, or defacement. The vulnerability is a classic stored client‑side XSS (CWE‑79).
Affected Systems
The affected software is Hono, the web framework from honojs. All releases prior to 4.13.7 are impacted; versions 4.13.7 and later address the issue.
Risk and Exploitability
The CVSS score for this vulnerability is 2.3, indicating low severity. EPSS data is not available and the flaw is not listed in the CISA KEV catalog. Exploitation requires an attacker to inject a controlled string that is subsequently rendered by the library during server‑side rendering; it is not a remote network exploit. While the technical impact is limited to the client side, the potential for data compromise and phishing makes it important to address promptly.
OpenCVE Enrichment
Github GHSA