AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-93981.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 30, 2026

Disclosure summary

### Summary `hono/jsx` does not HTML-escape a plain string placed directly as a child or `fallback` of `Suspense` or `ErrorBoundary`, as the only child of a `Context.Provider`, or as the root value of `renderToString()` / `renderToReadableStream()` from `hono/jsx/dom/server`. Such a string is emitted as markup instead of text. ### Details These paths stringify their input and treat the result as already-escaped HTML, so a plain string passes through unchanged. Notable cases: - `Suspense`: a string child, or a string `fallback` while a child suspends. With streaming, the fallback reaches the browser in the initial chunk. - `ErrorBoundary`: a string child alongside an asynchronous sibling. The all-synchronous case was fixed in 4.11.7 (GHSA-9r54-q6cx-xmh5). - `Context.Provider`: a single string child. Multiple children are escaped. - `hono/jsx/dom/server`: a string, or an array containing strings, passed as the root. A lone `{children}` forwarded by a wrapper component is enough to reach these paths. Strings wrapped in an element, values from `raw()` or the `html` helper, and client-side rendering with `hono/jsx/dom` are not affected. ### Impact An attacker who controls a string rende

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-hxh3-vqpv-xpqv

Open original source · Updated Sep 30, 2026

hono/jsx renders plain strings unescaped in boundary components, leading to XSS

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
npmhono< 4.13.74.13.7

Original records & references

PUBLISHED 2026-09-30T19:46:16-04:00
MODIFIED 2026-09-30T19:46:17-04:00
INGESTED 2026-10-06T11:45:02-04:00