Executive brief
A vulnerability in the Hono web framework could allow attackers to inject malicious scripts into web pages. Hono is a popular tool used by developers to build fast web applications. If an application uses a specific styling utility with data provided by a user, an attacker could take over user sessions or steal sensitive information like login credentials.
Technical details
A Cross-Site Scripting (XSS) vulnerability exists in Hono's `cx()` utility within the `hono/css` package. The `cx()` function composes CSS class names but incorrectly marks the resulting string as 'already escaped' without actually performing HTML entity encoding on the input. When this result is used in a JSX `class` attribute during server-side rendering (SSR), an attacker can provide input containing quotes to break out of the attribute and inject arbitrary HTML or JavaScript. This requires the application to pass untrusted, user-controlled strings to `cx()`. The issue is resolved in version 4.12.27.
Affected products
- honojs hono >= 4.0.0, < 4.12.27
Timeline
- 2026-06-23: patched: Fixed in version 4.12.27
- 2026-07-21: advisory: GitHub Advisory published