{"id":"GHSA-hxh3-vqpv-xpqv","summary":"hono/jsx renders plain strings unescaped in boundary components, leading to XSS","details":"### Summary\n\n`hono/jsx` does not HTML-escape a plain string placed directly as a child or `fallback` of `Suspense` or `ErrorBoundary`, as the only child of a `Context.Provider`, or as the root value of `renderToString()` / `renderToReadableStream()` from `hono/jsx/dom/server`. Such a string is emitted as markup instead of text.\n\n### Details\n\nThese paths stringify their input and treat the result as already-escaped HTML, so a plain string passes through unchanged. Notable cases:\n\n- `Suspense`: a string child, or a string `fallback` while a child suspends. With streaming, the fallback reaches the browser in the initial chunk.\n- `ErrorBoundary`: a string child alongside an asynchronous sibling. The all-synchronous case was fixed in 4.11.7 (GHSA-9r54-q6cx-xmh5).\n- `Context.Provider`: a single string child. Multiple children are escaped.\n- `hono/jsx/dom/server`: a string, or an array containing strings, passed as the root.\n\nA lone `{children}` forwarded by a wrapper component is enough to reach these paths. Strings wrapped in an element, values from `raw()` or the `html` helper, and client-side rendering with `hono/jsx/dom` are not affected.\n\n### Impact\n\nAn attacker who controls a string rendered in an affected position can inject arbitrary HTML into the server-rendered page, leading to cross-site scripting under the application's origin.\n\nThis issue affects applications that render untrusted strings directly in one of the positions above during server-side rendering.","aliases":["CVE-2026-93981"],"modified":"2026-10-01T00:00:05.224939184Z","published":"2026-09-30T23:46:16Z","database_specific":{"github_reviewed_at":"2026-09-30T23:46:16Z","nvd_published_at":null,"cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/honojs/hono/security/advisories/GHSA-hxh3-vqpv-xpqv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-93981"},{"type":"WEB","url":"https://github.com/honojs/hono/commit/2b8ed402cdab6dfc5e829b480806dcd8db94161e"},{"type":"PACKAGE","url":"https://github.com/honojs/hono"},{"type":"WEB","url":"https://github.com/honojs/hono/releases/tag/v4.13.7"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/hono-jsx-before-4.13.7-cross-site-scripting-via-unescaped-strings"}],"affected":[{"package":{"name":"hono","ecosystem":"npm","purl":"pkg:npm/hono"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.13.7"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-hxh3-vqpv-xpqv/GHSA-hxh3-vqpv-xpqv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N"}]}