CVE-2026-93981
### Summary `hono/jsx` does not HTML-escape a plain string placed directly as a child or `fallback` of `Suspense` or `ErrorBoundary`, as the only child of a `Context.Provider`, or as the root value of `renderToString()` / `renderToReadableStream()` from `hono/jsx/dom/server`. Such a string is emitted as markup instead of text. ### Details These paths stringify their input and treat the result as already-escaped HTML, so a plain string passes through unchanged. Notable cases: - `Suspense`: a string child, or a string `fallback` while a child suspends. With streaming, the fallback reaches the browser in the initial chunk. - `ErrorBoundary`: a string child alongside an asynchronous sibling. The all-synchronous case was fixed in 4.11.7 (GHSA-9r54-q6cx-xmh5). - `Context.Provider`: a single string child. Multiple children are escaped. - `hono/jsx/dom/server`: a string, or an array containing strings, passed as the root. A lone `{children}` forwarded by a wrapper component is enough to reach these paths. Strings wrapped in an element, values from `raw()` or the `html` helper, and client-side rendering with `hono/jsx/dom` are not affected. ### Impact An attacker who controls a string rendered in an affected position can inject arbitrary HTML into the server-rendered page, leading to cross-site scripting under the application's origin. This issue affects applications that render untrusted strings directly in one of the positions above during server-side rendering.
Properties
- severity
- medium
- summary
- hono/jsx renders plain strings unescaped in boundary components, leading to XSS
- cvss_score
- 4.7
- retrieved_at
- 2026-09-30T23:58:31+00:00
- ghsa_published
- 2026-09-30T23:46:16Z
- source_url
- https://github.com/advisories/GHSA-hxh3-vqpv-xpqv
- ghsa_updated
- 2026-09-30T23:46:17Z
- ghsa_id
- GHSA-hxh3-vqpv-xpqv
- last_source
- GitHub Advisory Database
- cve_id
- CVE-2026-93981
- cvss_vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
- signal_observed_at
- 2026-09-30T23:58:31+00:00
- is_ghsa_only
- false
Related Entities (4)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph