Cross-site scripting in hono - CVE-2026-93981
Published: September 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject arbitrary HTML and execute cross-site scripting in the application's origin.
The vulnerability exists due to improper neutralization of input during web page generation in hono/jsx server-side rendering boundary components when rendering an attacker-controlled plain string directly in an affected position. A remote attacker can supply a crafted string that is emitted as markup to inject arbitrary HTML and execute cross-site scripting in the application's origin.
User interaction is required to view the server-rendered page containing the crafted string.