Vulnerability GHSA-hxh3-vqpv-xpqv

Medium Risk
MEDIUM RISK
CVSS Score: 4.7
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
7 hours ago
September 30, 2026 at 11:46 PM UTC
hono/jsx renders plain strings unescaped in boundary components, leading to XSS
0.0.1 - 4.13.6
0.0.1 - 4.13.6

Summary

hono/jsx renders plain strings unescaped in boundary components, leading to XSS

Details

Summary

hono/jsx does not HTML-escape a plain string placed directly as a child or fallback of Suspense or ErrorBoundary, as the only child of a Context.Provider, or as the root value of renderToString() / renderToReadableStream() from hono/jsx/dom/server. Such a string is emitted as markup instead of text.

Details

These paths stringify their input and treat the result as already-escaped HTML, so a plain string passes through unchanged. Notable cases:

  • Suspense: a string child, or a string fallback while a child suspends. With streaming, the fallback reaches the browser in the initial chunk.
  • ErrorBoundary: a string child alongside an asynchronous sibling. The all-synchronous case was fixed in 4.11.7 (GHSA-9r54-q6cx-xmh5).
  • Context.Provider: a single string child. Multiple children are escaped.
  • hono/jsx/dom/server: a string, or an array containing strings, passed as the root.

A lone {children} forwarded by a wrapper component is enough to reach these paths. Strings wrapped in an element, values from raw() or the html helper, and client-side rendering with hono/jsx/dom are not affected.

Impact

An attacker who controls a string rendered in an affected position can inject arbitrary HTML into the server-rendered page, leading to cross-site scripting under the application's origin.

This issue affects applications that render untrusted strings directly in one of the positions above during server-side rendering.

Impacted packages

Timeline

Published
7 hours ago
September 30, 2026 at 11:46 PM UTC
Fixed (4.13.7)
26 days ago
September 04, 2026 at 07:18 PM UTC
Last Modified
7 hours ago
October 01, 2026 at 12:00 AM UTC