GHSA-hxh3-vqpv-xpqv

Suggest an improvement
Source
https://github.com/advisories/GHSA-hxh3-vqpv-xpqv
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-hxh3-vqpv-xpqv/GHSA-hxh3-vqpv-xpqv.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hxh3-vqpv-xpqv
Aliases
Published
2026-09-30T23:46:16Z
Modified
2026-10-01T00:00:05Z
Severity
  • 4.7 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
hono/jsx renders plain strings unescaped in boundary components, leading to XSS
Details

Summary

hono/jsx does not HTML-escape a plain string placed directly as a child or fallback of Suspense or ErrorBoundary, as the only child of a Context.Provider, or as the root value of renderToString() / renderToReadableStream() from hono/jsx/dom/server. Such a string is emitted as markup instead of text.

Details

These paths stringify their input and treat the result as already-escaped HTML, so a plain string passes through unchanged. Notable cases:

  • Suspense: a string child, or a string fallback while a child suspends. With streaming, the fallback reaches the browser in the initial chunk.
  • ErrorBoundary: a string child alongside an asynchronous sibling. The all-synchronous case was fixed in 4.11.7 (GHSA-9r54-q6cx-xmh5).
  • Context.Provider: a single string child. Multiple children are escaped.
  • hono/jsx/dom/server: a string, or an array containing strings, passed as the root.

A lone {children} forwarded by a wrapper component is enough to reach these paths. Strings wrapped in an element, values from raw() or the html helper, and client-side rendering with hono/jsx/dom are not affected.

Impact

An attacker who controls a string rendered in an affected position can inject arbitrary HTML into the server-rendered page, leading to cross-site scripting under the application's origin.

This issue affects applications that render untrusted strings directly in one of the positions above during server-side rendering.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-09-30T23:46:16Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

npm / hono

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.13.7

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-hxh3-vqpv-xpqv/GHSA-hxh3-vqpv-xpqv.json"