GHSA-m6mh-2hw2-555xMediumCVSS 5.4

Ammonia: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Published
September 29, 2026
Last Modified
September 29, 2026

🔗 CVE IDs covered (1)

📋 Description

The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.

<svg xmlns="http://www.w3.org/2000/svg">
  <a>
    <set attributeName="href" to="javascript:alert('SET_XSS')"></set>
    <text y="30">Click set</text>
  </a>
</svg>

Impact

Allows stored XSS in applications that allow the animate and set tags.

Patches

Fixed in 3.3.3, 4.0.3, and 4.1.4

Workarounds

Do not enable the animate or set tags.

🎯 Affected products3

  • rust/ammonia:< 3.3.2
  • rust/ammonia:>= 4.0.0, <= 4.0.2
  • rust/ammonia:>= 4.1.2, <= 4.1.3

🔗 References (9)