Search

Find a vulnerability

Search criteria

    Related vulnerabilities

    GHSA-M6MH-2HW2-555X

    Vulnerability from github – Published: 2026-09-29 23:09 – Updated: 2026-09-29 23:09
    VLAI
    Summary
    Ammonia: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
    Details

    The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.

    <svg xmlns="http://www.w3.org/2000/svg">
      <a>
        <set attributeName="href" to="javascript:alert('SET_XSS')"></set>
        <text y="30">Click set</text>
      </a>
    </svg>
    

    Impact

    Allows stored XSS in applications that allow the animate and set tags.

    Patches

    Fixed in 3.3.3, 4.0.3, and 4.1.4

    Workarounds

    Do not enable the animate or set tags.

    Show details on source website

    {
      "affected": [
        {
          "database_specific": {
            "last_known_affected_version_range": "\u003c 3.3.2"
          },
          "package": {
            "ecosystem": "crates.io",
            "name": "ammonia"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0"
                },
                {
                  "fixed": "3.3.3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "database_specific": {
            "last_known_affected_version_range": "\u003c= 4.0.2"
          },
          "package": {
            "ecosystem": "crates.io",
            "name": "ammonia"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "4.0.0"
                },
                {
                  "fixed": "4.0.3"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        },
        {
          "database_specific": {
            "last_known_affected_version_range": "\u003c= 4.1.3"
          },
          "package": {
            "ecosystem": "crates.io",
            "name": "ammonia"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "4.1.2"
                },
                {
                  "fixed": "4.1.4"
                }
              ],
              "type": "ECOSYSTEM"
            }
          ]
        }
      ],
      "aliases": [
        "CVE-2026-102342"
      ],
      "database_specific": {
        "cwe_ids": [
          "CWE-79"
        ],
        "github_reviewed": true,
        "github_reviewed_at": "2026-09-29T23:09:16Z",
        "nvd_published_at": null,
        "severity": "MODERATE"
      },
      "details": "The following SVG will produce a link with a `javascript` scheme. If the user clicks this link, they will run it.\n\n```svg\n\u003csvg xmlns=\"http://www.w3.org/2000/svg\"\u003e\n  \u003ca\u003e\n    \u003cset attributeName=\"href\" to=\"javascript:alert(\u0027SET_XSS\u0027)\"\u003e\u003c/set\u003e\n    \u003ctext y=\"30\"\u003eClick set\u003c/text\u003e\n  \u003c/a\u003e\n\u003c/svg\u003e\n```\n\n### Impact\n\nAllows stored XSS in applications that allow the `animate` and `set` tags.\n\n### Patches\n\nFixed in 3.3.3, 4.0.3, and 4.1.4\n\n### Workarounds\n\nDo not enable the `animate` or `set` tags.",
      "id": "GHSA-m6mh-2hw2-555x",
      "modified": "2026-09-29T23:09:16Z",
      "published": "2026-09-29T23:09:16Z",
      "references": [
        {
          "type": "WEB",
          "url": "https://github.com/rust-ammonia/ammonia/security/advisories/GHSA-m6mh-2hw2-555x"
        },
        {
          "type": "WEB",
          "url": "https://github.com/rust-ammonia/ammonia/pull/250"
        },
        {
          "type": "WEB",
          "url": "https://github.com/rust-ammonia/ammonia/pull/251"
        },
        {
          "type": "WEB",
          "url": "https://github.com/rust-ammonia/ammonia/pull/252"
        },
        {
          "type": "WEB",
          "url": "https://github.com/rust-ammonia/ammonia/commit/9394bd81179e756cb911314deabd943f1a9c8989"
        },
        {
          "type": "WEB",
          "url": "https://github.com/rust-ammonia/ammonia/commit/9e3335e2dd8ab07346ff7997f20662a3da4023f6"
        },
        {
          "type": "WEB",
          "url": "https://github.com/rust-ammonia/ammonia/commit/d2ae1547f478bd84d158bc5e57f5d31437dc4d8d"
        },
        {
          "type": "PACKAGE",
          "url": "https://github.com/rust-ammonia/ammonia"
        },
        {
          "type": "WEB",
          "url": "https://rustsec.org/advisories/RUSTSEC-2026-0213.html"
        }
      ],
      "schema_version": "1.4.0",
      "severity": [
        {
          "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
          "type": "CVSS_V3"
        }
      ],
      "summary": "Ammonia: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)"
    }

    RUSTSEC-2026-0213 (CVE-2026-102342)

    Vulnerability from osv_rustsec – Published: 2026-07-21 12:00 – Updated: 2026-09-30 07:15 – Source website
    VLAI
    Summary
    XSS in ammonia via SVG `animate` and `set` animation tags
    Details

    The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.

    <svg xmlns="http://www.w3.org/2000/svg">
      <a>
        <set attributeName="href" to="javascript:alert('SET_XSS')"></set>
        <text y="30">Click set</text>
      </a>
    </svg>
    

    Ammonia did not apply attribute filters based on attributeName, so the contents of the to, from, and values tags were not sanitized as URLs.

    Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default.


    Discovered by: Younghun Ko (@koyokr)


    {
      "affected": [
        {
          "database_specific": {
            "categories": [
              "format-injection"
            ],
            "cvss": null,
            "informational": null
          },
          "ecosystem_specific": {
            "affected_functions": null,
            "affects": {
              "arch": [],
              "functions": [],
              "os": []
            }
          },
          "package": {
            "ecosystem": "crates.io",
            "name": "ammonia",
            "purl": "pkg:cargo/ammonia"
          },
          "ranges": [
            {
              "events": [
                {
                  "introduced": "0.0.0-0"
                },
                {
                  "fixed": "3.3.3"
                },
                {
                  "introduced": "4.0.0"
                },
                {
                  "fixed": "4.0.3"
                },
                {
                  "introduced": "4.1.0"
                },
                {
                  "fixed": "4.1.4"
                }
              ],
              "type": "SEMVER"
            }
          ],
          "versions": []
        }
      ],
      "aliases": [
        "CVE-2026-102342",
        "GHSA-m6mh-2hw2-555x"
      ],
      "database_specific": {
        "license": "CC0-1.0"
      },
      "details": "The following SVG will produce a link with a javascript scheme.\nIf the user clicks this link, they will run it.\n\n```xml\n\u003csvg xmlns=\"http://www.w3.org/2000/svg\"\u003e\n  \u003ca\u003e\n    \u003cset attributeName=\"href\" to=\"javascript:alert(\u0027SET_XSS\u0027)\"\u003e\u003c/set\u003e\n    \u003ctext y=\"30\"\u003eClick set\u003c/text\u003e\n  \u003c/a\u003e\n\u003c/svg\u003e\n```\n\nAmmonia did not apply attribute filters based on `attributeName`,\nso the contents of the `to`, `from`, and `values` tags were not sanitized as URLs.\n\nApplications that do not explicitly allow either of these tags should not be affected,\nsince neither are allowed by default.\n\n---\n\n**Discovered by:** [Younghun Ko (@koyokr)](https://github.com/koyokr)",
      "id": "RUSTSEC-2026-0213",
      "modified": "2026-09-30T07:15:39Z",
      "published": "2026-07-21T12:00:00Z",
      "references": [
        {
          "type": "PACKAGE",
          "url": "https://crates.io/crates/ammonia"
        },
        {
          "type": "ADVISORY",
          "url": "https://rustsec.org/advisories/RUSTSEC-2026-0213.html"
        }
      ],
      "related": [],
      "severity": [],
      "summary": "XSS in ammonia via SVG `animate` and `set` animation tags"
    }