hono is vulnerable to CSS Injection
43
Medium Risk
Server-side JSX style-object serialization escapes for HTML attribute context but not for CSS declaration context. Untrusted style values or property names can inject additional CSS declarations into the rendered style attribute. This enables UI manipulation and style-driven exfiltration patterns without direct JavaScript execution. The fix adds stricter CSS-context handling so injected declaration boundaries are not interpreted as attacker-controlled CSS.
You are affected if you are using a version that falls within the vulnerable range.
hono is vulnerable to CSS Injection in versions 0.0.1 - 4.12.16.
Upgrade the hono library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant