Disclosure summary
### Summary `hono/jsx` does not HTML-escape a plain string placed directly as a child or `fallback` of `Suspense` or `ErrorBoundary`, as the only child of a `Context.Provider`, or as the root value of `renderToString()` / `renderToReadableStream()` from `hono/jsx/dom/server`. Such a string is emitted as markup instead of text. ### Details These paths stringify their input and treat the result as already-escaped HTML, so a plain string passes through unchanged. Notable cases: - `Suspense`: a string child, or a string `fallback` while a child suspends. With streaming, the fallback reaches the browser in the initial chunk. - `ErrorBoundary`: a string child alongside an asynchronous sibling. The all-synchronous case was fixed in 4.11.7 (GHSA-9r54-q6cx-xmh5). - `Context.Provider`: a single string child. Multiple children are escaped. - `hono/jsx/dom/server`: a string, or an array containing strings, passed as the root. A lone `{children}` forwarded by a wrapper component is enough to reach these paths. Strings wrapped in an element, values from `raw()` or the `html` helper, and client-side rendering with `hono/jsx/dom` are not affected. ### Impact An attacker who controls a string rende
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-hxh3-vqpv-xpqv
Open original source · Updated Sep 30, 2026
hono/jsx renders plain strings unescaped in boundary components, leading to XSS
Source severity: MEDIUM / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | hono | < 4.13.7 | 4.13.7 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-09-30T19:46:16-04:00
MODIFIED 2026-09-30T19:46:17-04:00
INGESTED 2026-10-06T11:45:02-04:00