Junglewise Threat Intelligence

CVE-2026-59895: Hono XSS in hono/css cx() utility

CVE-2026-59895 · Severity: medium · CVSS 6.1 · Published 2026-07-08

Technologies: Honojs Hono. Vendors: npm.

Executive brief

A vulnerability in the Hono web framework could allow attackers to inject malicious scripts into web pages. Hono is a popular tool used by developers to build fast web applications. If an application uses a specific styling utility with data provided by a user, an attacker could take over user sessions or steal sensitive information like login credentials.

Technical details

A Cross-Site Scripting (XSS) vulnerability exists in Hono's `cx()` utility within the `hono/css` package. The `cx()` function composes CSS class names but incorrectly marks the resulting string as 'already escaped' without actually performing HTML entity encoding on the input. When this result is used in a JSX `class` attribute during server-side rendering (SSR), an attacker can provide input containing quotes to break out of the attribute and inject arbitrary HTML or JavaScript. This requires the application to pass untrusted, user-controlled strings to `cx()`. The issue is resolved in version 4.12.27.

Affected products

  • honojs hono >= 4.0.0, < 4.12.27

Timeline

  • 2026-06-23: patched: Fixed in version 4.12.27
  • 2026-07-21: advisory: GitHub Advisory published

References

Related threats