Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 19 Sep 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside an asynchronous sibling, as the single child of a Context.Provider, or as the root value passed to renderToString() or renderToReadableStream() from hono/jsx/dom/server. These paths stringify their input and treat the result as already-escaped markup, so an attacker who controls such a string during server-side rendering can inject arbitrary HTML and execute script under the application's origin. | |
| Title | hono/jsx before 4.13.7 Cross-Site Scripting via Unescaped Strings | |
| First Time appeared |
Hono
Hono hono |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:hono:hono:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Hono
Hono hono |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-19T11:53:34.294Z
Reserved: 2026-09-19T10:55:49.092Z
Link: CVE-2026-93981
No data.
Status : Deferred
Published: 2026-09-19T12:16:41.080
Modified: 2026-09-19T12:16:41.223
Link: CVE-2026-93981
No data.
OpenCVE Enrichment
No data.
