Junglewise Threat Intelligence

CVE-2026-24771: Hono XSS in ErrorBoundary component

CVE-2026-24771 · Severity: low · CVSS 3.1 · Published 2026-01-28

Technologies: hono (npm). Vendors: Hono, npm.

Executive brief

Hono is a popular web framework library for building JavaScript applications. The ErrorBoundary component, which is used to handle and display errors gracefully, contains a cross-site scripting (XSS) vulnerability that allows attackers to inject and execute malicious scripts in users' browsers when the component processes untrusted input. This could enable attackers to steal sessions, extract sensitive data, or perform unauthorized actions on behalf of victims.

Technical details

The vulnerability is a stored/reflected XSS (CWE-79) in the ErrorBoundary component of hono/jsx (src/jsx/components.ts). The component bypasses the library's default HTML escaping behavior by forcing certain output paths to be treated as raw HTML. When developers pass user-controlled strings directly as children or when fallbackRender returns user-controlled strings (such as error messages reflecting attacker input), these strings are rendered unescaped as HTML. The vulnerability requires that an application renders untrusted user input within ErrorBoundary without appropriate escaping or sanitization. Exploitation is network-accessible but requires user interaction (reflected XSS). The fix is available in version 4.11.7 and later.

Affected products

  • Hono Hono before 4.11.7

Timeline

  • 2026-01-27: disclosed: NVD published
  • 2026-01-28: advisory: GitHub advisory GHSA-9r54-q6cx-xmh5 published
  • 2026-01-28: patched: Fix available in version 4.11.7

References

Related threats