GHSA-m6mh-2hw2-555xMediumCVSS 5.4
Ammonia: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
🔗 CVE IDs covered (1)
📋 Description
The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
<svg xmlns="http://www.w3.org/2000/svg">
<a>
<set attributeName="href" to="javascript:alert('SET_XSS')"></set>
<text y="30">Click set</text>
</a>
</svg>
Impact
Allows stored XSS in applications that allow the animate and set tags.
Patches
Fixed in 3.3.3, 4.0.3, and 4.1.4
Workarounds
Do not enable the animate or set tags.
🎯 Affected products3
- rust/ammonia:< 3.3.2
- rust/ammonia:>= 4.0.0, <= 4.0.2
- rust/ammonia:>= 4.1.2, <= 4.1.3
🔗 References (9)
- https://github.com/rust-ammonia/ammonia/security/advisories/GHSA-m6mh-2hw2-555x
- https://github.com/rust-ammonia/ammonia/pull/250
- https://github.com/rust-ammonia/ammonia/pull/251
- https://github.com/rust-ammonia/ammonia/pull/252
- https://github.com/rust-ammonia/ammonia/commit/9394bd81179e756cb911314deabd943f1a9c8989
- https://github.com/rust-ammonia/ammonia/commit/9e3335e2dd8ab07346ff7997f20662a3da4023f6
- https://github.com/rust-ammonia/ammonia/commit/d2ae1547f478bd84d158bc5e57f5d31437dc4d8d
- https://rustsec.org/advisories/RUSTSEC-2026-0213.html
- https://github.com/advisories/GHSA-m6mh-2hw2-555x