PT-2026-51785 · Npm · Hono

·

CVE-2026-56761

·

Published

2026-04-16

·

Updated

2026-07-27

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions hono versions prior to 4.12.14
Description An HTML injection issue exists in the JSX server-side rendering (SSR) process. Attackers can inject unintended HTML by using malformed attribute names. By crafting attribute keys that include characters such as quotes or angle brackets, an attacker can break HTML tag boundaries to inject arbitrary attributes or elements.
Recommendations Update hono to version 4.12.14 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-56761
GHSA-458J-XX4X-4375

Affected Products

Hono