Hono是Hono团队开源的一个用 TypeScript 编写的 Web 框架。 Hono 4.0.0版本至4.12.27之前版本存在安全漏洞,该漏洞源于hono/css中的cx()函数将纯字符串组合为class名,但未对输入进行HTML转义即标记为已转义,允许在服务器端渲染期间使用不可信的className值,从而突破属性并注入任意标记。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59896 | 6.5 MEDIUM | hono/jsx does not isolate context per request, leading to cross-request data disclosure |
| CVE-2026-59897 | 4.8 MEDIUM | Hono: API Gateway v1 adapter can drop a distinct repeated request header value during de-d |
No comments yet