mediumCVSS 4.7Vulnerability

CVE-2026-93981

### Summary `hono/jsx` does not HTML-escape a plain string placed directly as a child or `fallback` of `Suspense` or `ErrorBoundary`, as the only child of a `Context.Provider`, or as the root value of `renderToString()` / `renderToReadableStream()` from `hono/jsx/dom/server`. Such a string is emitted as markup instead of text. ### Details These paths stringify their input and treat the result as already-escaped HTML, so a plain string passes through unchanged. Notable cases: - `Suspense`: a string child, or a string `fallback` while a child suspends. With streaming, the fallback reaches the browser in the initial chunk. - `ErrorBoundary`: a string child alongside an asynchronous sibling. The all-synchronous case was fixed in 4.11.7 (GHSA-9r54-q6cx-xmh5). - `Context.Provider`: a single string child. Multiple children are escaped. - `hono/jsx/dom/server`: a string, or an array containing strings, passed as the root. A lone `{children}` forwarded by a wrapper component is enough to reach these paths. Strings wrapped in an element, values from `raw()` or the `html` helper, and client-side rendering with `hono/jsx/dom` are not affected. ### Impact An attacker who controls a string rendered in an affected position can inject arbitrary HTML into the server-rendered page, leading to cross-site scripting under the application's origin. This issue affects applications that render untrusted strings directly in one of the positions above during server-side rendering.

Properties

severity
medium
summary
hono/jsx renders plain strings unescaped in boundary components, leading to XSS
cvss_score
4.7
retrieved_at
2026-09-30T23:58:31+00:00
ghsa_published
2026-09-30T23:46:16Z
source_url
https://github.com/advisories/GHSA-hxh3-vqpv-xpqv
ghsa_updated
2026-09-30T23:46:17Z
ghsa_id
GHSA-hxh3-vqpv-xpqv
last_source
GitHub Advisory Database
cve_id
CVE-2026-93981
cvss_vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
signal_observed_at
2026-09-30T23:58:31+00:00
is_ghsa_only
false

Related Entities (4)

VULNERABLE_TO (1)

←[Software]npm/hono

AFFECTS (1)

→[Software]npm/hono

HAS_WEAKNESS (1)

→[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-93981 (CVSS 4.7) — Ninja Signal Threat Intelligence | Ninja Signal