GHSA-458j-xx4x-4375: hono Improperly Handles JSX Attribute Names Allows HTML Injection in hono/jsx SSR
Improper handling of JSX attribute names in hono/jsx allows malformed attribute keys to corrupt the generated HTML output.
When untrusted input is used as attribute keys during server-side rendering, specially crafted keys can break out of attribute or tag boundaries and inject unintended HTML.
References
Code Behaviors & Features
Detect and mitigate GHSA-458j-xx4x-4375 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →