CVE-2026-59895
EUVD-2026-4232708.07.2026, 17:17
Hono is a Web application framework that provides support for any JavaScript runtime. From 4.0.0 before 4.12.27, cx() in hono/css composes class names from plain strings but marks the result as already escaped without HTML-escaping the input, allowing untrusted className values used in a JSX class attribute during server-side rendering to break out of the attribute and inject arbitrary markup. This issue is fixed in version 4.12.27.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| hono | hono | 4.0.0 ≤ 𝑥 < 4.12.27 |
𝑥
= Vulnerable software versions