CVE-2026-59895

MEDIUM

Hono: Server-Side XSS via JSX Escaping Bypass in cx() Utility

Title source: cna
STIX 2.1

Description

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values used in a JSX class attribute during server-side rendering to break out of the attribute and inject arbitrary markup. This issue is fixed in version 4.12.27.

Scores

CVSS v3 6.1
EPSS 0.0020
EPSS Percentile 9.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-116 CWE-79
Status published
Products (3)
hono/hono 4.0.0 - 4.12.27
honojs/hono >= 4.0.0, < 4.12.27
npm/hono 4.0.0 - 4.12.27npm
Published Jul 08, 2026
Tracked Since Jul 08, 2026