GHSA-hxh3-vqpv-xpqv: XSS
Summary
hono/jsx does not HTML-escape a plain string placed directly as a child or fallback of Suspense or ErrorBoundary, as the only child of a Context.Provider, or as the root value of renderToString() / renderToReadableStream() from hono/jsx/dom/server. Such a string is emitted as markup instead of text.
Details
These paths stringify their input and treat the result as already-escaped HTML, so a plain string passes through unchanged. Notable cases:
- Suspense: a string child, or a string fallback while a child suspends. With streaming, the fallback reaches the browser in the initial chunk. - ErrorBoundary: a string child alongside an asynchronous sibling. The all-synchronous case was fixed in 4.11.7 (GHSA-9r54-q6cx-xmh5). - Context.Provider: a single string child. Multiple children are escaped. - hono/jsx/dom/server: a string, or an array containing strings, passed as the root.
A lone {children} forwarded by a wrapper component is enough to reach these paths. Strings wrapped in an element, values from raw() or the html helper, and client-side rendering with hono/jsx/dom are not affected.
Impact
An attacker who controls a string rendered in an affected position can inject arbitrary HTML into the server-rendered page, leading to cross-site scripting under the application's origin.
This issue affects applications that render untrusted strings directly in one of the positions above during server-side rendering.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/honoto a version that resolves this vulnerability.Fixed in 4.13.7 - Upgrade
Upgrade
honoto a version that resolves this vulnerability.Fixed in 4.11.7Patch GHSA-9r54-q6cx-xmh5
Event History
Frequently Asked Questions
What conditions must be present for exploitation?
An attacker must control a string that reaches one of the affected server-rendering paths. The string is emitted as markup rather than escaped text, enabling cross-site scripting when it contains attacker-controlled HTML or script-capable markup.
Which rendering patterns should be reviewed?
Review Suspense string children and fallbacks, ErrorBoundary string children with an asynchronous sibling, Context.Provider instances with exactly one string child, and renderToString() or renderToReadableStream() calls that receive a string or an array containing strings as the root value. Wrapper components that forward a lone {children} can also reach the affected paths.
Are all uses of hono/jsx affected?
No. Strings wrapped in an element, values produced by raw() or the html helper, and client-side rendering with hono/jsx/dom are not affected. Context.Provider with multiple children escapes strings.
Is there a streaming-specific exposure to prioritize?
Yes. When a Suspense child suspends, a string fallback can be sent to the browser in the initial streaming chunk. Prioritize server-side streaming routes that render attacker-influenced fallback content.