CVE-2026-93981
Last modified
CVE-2026-93981 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside an asynchronous sibling, as the single child of a Context.Provider, or as the root value passed to renderToString() or renderToReadableStream() from hono/jsx/dom/server. These paths stringify their input and treat the result as already-escaped markup, so an attacker who controls such a string during server-side rendering can inject arbitrary HTML and execute script under the application's origin..
Description
hono before 4.13.7 fails to HTML-escape plain strings rendered by hono/jsx as a child or fallback of Suspense, as a string child of ErrorBoundary alongside an asynchronous sibling, as the single child of a Context.Provider, or as the root value passed to renderToString() or renderToReadableStream() from hono/jsx/dom/server. These paths stringify their input and treat the result as already-escaped markup, so an attacker who controls such a string during server-side rendering can inject arbitrary HTML and execute script under the application's origin.
Metrics
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-93981?
How severe is CVE-2026-93981?
How do I fix CVE-2026-93981?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-93976A vulnerability was found in code-projects Assessment Manage…2.4
- CVE-2026-93977A vulnerability was determined in code-projects Assessment M…3.5
- CVE-2026-93978A vulnerability was identified in code-projects Internship M…7.3
- CVE-2026-93979A security flaw has been discovered in code-projects Interns…7.3
- CVE-2026-9398A security vulnerability has been detected in Besen BS20 EV …3.1
- CVE-2026-93980A weakness has been identified in code-projects Internship M…7.3
- CVE-2026-93982OpenPanel through commit bad75bdd writes Model Context Proto…3.3
- CVE-2026-93983OpenPanel through commit bad75bdd fails to escape property k…5
- CVE-2026-93984OpenPanel tracking API through commit bad75bddc74d12d36cfb84…5.3
- CVE-2026-93985OpenPanel js-runtime through commit bad75bdd contains a sand…9.9
- CVE-2026-93986rclone before 1.75.1 fails to confine names from server and …3.1
- CVE-2026-93987rclone versions 1.56.0 through 1.75.0 contain a path travers…3.4
Are you affected by CVE-2026-93981?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
