CVE-2026-93981
4.7 MEDIUMpublic exploit availablePublished 2026-09-19 · Updated 2026-09-21
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside an asynchronous sibling, as the single child of a Context.Provider, or as the root value passed to renderToString() or renderToReadableStream() from hono/jsx/dom/server. These paths stringify their input and treat the result as already-escaped markup, so an attacker who controls such a string during server-side rendering can inject arbitrary HTML and execute script under the application's origin.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N
Weaknesses
CWE-79
Public exploit & PoC references
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- LOWCVE-2025-15677
- LOWCVE-2025-15698
- MEDIUMCVE-2025-71419PoC
- UNSCOREDCVE-2026-10032PoC
- MEDIUMCVE-2026-11608
- MEDIUMCVE-2026-12402
- MEDIUMCVE-2026-1256
- MEDIUMCVE-2026-13770
Related by shared AI tags and CWE weakness class. Browse the full archive.