GHSA-hxh3-vqpv-xpqv: XSS

Published Sep 30, 2026
·
Updated

Summary

hono/jsx does not HTML-escape a plain string placed directly as a child or fallback of Suspense or ErrorBoundary, as the only child of a Context.Provider, or as the root value of renderToString() / renderToReadableStream() from hono/jsx/dom/server. Such a string is emitted as markup instead of text.

Details

These paths stringify their input and treat the result as already-escaped HTML, so a plain string passes through unchanged. Notable cases:

- Suspense: a string child, or a string fallback while a child suspends. With streaming, the fallback reaches the browser in the initial chunk. - ErrorBoundary: a string child alongside an asynchronous sibling. The all-synchronous case was fixed in 4.11.7 (GHSA-9r54-q6cx-xmh5). - Context.Provider: a single string child. Multiple children are escaped. - hono/jsx/dom/server: a string, or an array containing strings, passed as the root.

A lone {children} forwarded by a wrapper component is enough to reach these paths. Strings wrapped in an element, values from raw() or the html helper, and client-side rendering with hono/jsx/dom are not affected.

Impact

An attacker who controls a string rendered in an affected position can inject arbitrary HTML into the server-rendered page, leading to cross-site scripting under the application's origin.

This issue affects applications that render untrusted strings directly in one of the positions above during server-side rendering.

Affected Software

1 affected componentFixes available
npm/hono<4.13.7
4.13.7

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/hono to a version that resolves this vulnerability.

    Fixed in 4.13.7
  2. Upgrade

    Upgrade hono to a version that resolves this vulnerability.

    Fixed in 4.11.7Patch GHSA-9r54-q6cx-xmh5

Event History

Sep 30, 2026
Advisory Published
via GitHub·11:46 PM
Data Sourced
via GitHub·11:46 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What conditions must be present for exploitation?

An attacker must control a string that reaches one of the affected server-rendering paths. The string is emitted as markup rather than escaped text, enabling cross-site scripting when it contains attacker-controlled HTML or script-capable markup.

2

Which rendering patterns should be reviewed?

Review Suspense string children and fallbacks, ErrorBoundary string children with an asynchronous sibling, Context.Provider instances with exactly one string child, and renderToString() or renderToReadableStream() calls that receive a string or an array containing strings as the root value. Wrapper components that forward a lone {children} can also reach the affected paths.

3

Are all uses of hono/jsx affected?

No. Strings wrapped in an element, values produced by raw() or the html helper, and client-side rendering with hono/jsx/dom are not affected. Context.Provider with multiple children escapes strings.

4

Is there a streaming-specific exposure to prioritize?

Yes. When a Suspense child suspends, a string fallback can be sent to the browser in the initial streaming chunk. Prioritize server-side streaming routes that render attacker-influenced fallback content.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203