Search
Find a vulnerability
Search criteria
Related vulnerabilities
GHSA-M6MH-2HW2-555X
Vulnerability from github – Published: 2026-09-29 23:09 – Updated: 2026-09-29 23:09
VLAI
Summary
Ammonia: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Details
The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
<svg xmlns="http://www.w3.org/2000/svg">
<a>
<set attributeName="href" to="javascript:alert('SET_XSS')"></set>
<text y="30">Click set</text>
</a>
</svg>
Impact
Allows stored XSS in applications that allow the animate and set tags.
Patches
Fixed in 3.3.3, 4.0.3, and 4.1.4
Workarounds
Do not enable the animate or set tags.
Severity
5.4 (Medium)
{
"affected": [
{
"database_specific": {
"last_known_affected_version_range": "\u003c 3.3.2"
},
"package": {
"ecosystem": "crates.io",
"name": "ammonia"
},
"ranges": [
{
"events": [
{
"introduced": "0"
},
{
"fixed": "3.3.3"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"database_specific": {
"last_known_affected_version_range": "\u003c= 4.0.2"
},
"package": {
"ecosystem": "crates.io",
"name": "ammonia"
},
"ranges": [
{
"events": [
{
"introduced": "4.0.0"
},
{
"fixed": "4.0.3"
}
],
"type": "ECOSYSTEM"
}
]
},
{
"database_specific": {
"last_known_affected_version_range": "\u003c= 4.1.3"
},
"package": {
"ecosystem": "crates.io",
"name": "ammonia"
},
"ranges": [
{
"events": [
{
"introduced": "4.1.2"
},
{
"fixed": "4.1.4"
}
],
"type": "ECOSYSTEM"
}
]
}
],
"aliases": [
"CVE-2026-102342"
],
"database_specific": {
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-29T23:09:16Z",
"nvd_published_at": null,
"severity": "MODERATE"
},
"details": "The following SVG will produce a link with a `javascript` scheme. If the user clicks this link, they will run it.\n\n```svg\n\u003csvg xmlns=\"http://www.w3.org/2000/svg\"\u003e\n \u003ca\u003e\n \u003cset attributeName=\"href\" to=\"javascript:alert(\u0027SET_XSS\u0027)\"\u003e\u003c/set\u003e\n \u003ctext y=\"30\"\u003eClick set\u003c/text\u003e\n \u003c/a\u003e\n\u003c/svg\u003e\n```\n\n### Impact\n\nAllows stored XSS in applications that allow the `animate` and `set` tags.\n\n### Patches\n\nFixed in 3.3.3, 4.0.3, and 4.1.4\n\n### Workarounds\n\nDo not enable the `animate` or `set` tags.",
"id": "GHSA-m6mh-2hw2-555x",
"modified": "2026-09-29T23:09:16Z",
"published": "2026-09-29T23:09:16Z",
"references": [
{
"type": "WEB",
"url": "https://github.com/rust-ammonia/ammonia/security/advisories/GHSA-m6mh-2hw2-555x"
},
{
"type": "WEB",
"url": "https://github.com/rust-ammonia/ammonia/pull/250"
},
{
"type": "WEB",
"url": "https://github.com/rust-ammonia/ammonia/pull/251"
},
{
"type": "WEB",
"url": "https://github.com/rust-ammonia/ammonia/pull/252"
},
{
"type": "WEB",
"url": "https://github.com/rust-ammonia/ammonia/commit/9394bd81179e756cb911314deabd943f1a9c8989"
},
{
"type": "WEB",
"url": "https://github.com/rust-ammonia/ammonia/commit/9e3335e2dd8ab07346ff7997f20662a3da4023f6"
},
{
"type": "WEB",
"url": "https://github.com/rust-ammonia/ammonia/commit/d2ae1547f478bd84d158bc5e57f5d31437dc4d8d"
},
{
"type": "PACKAGE",
"url": "https://github.com/rust-ammonia/ammonia"
},
{
"type": "WEB",
"url": "https://rustsec.org/advisories/RUSTSEC-2026-0213.html"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"type": "CVSS_V3"
}
],
"summary": "Ammonia: Improper Neutralization of Input During Web Page Generation (\u0027Cross-site Scripting\u0027)"
}
RUSTSEC-2026-0213 (CVE-2026-102342)
Vulnerability from osv_rustsec – Published: 2026-07-21 12:00 – Updated: 2026-09-30 07:15 – Source website
VLAI
Summary
XSS in ammonia via SVG `animate` and `set` animation tags
Details
The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
<svg xmlns="http://www.w3.org/2000/svg">
<a>
<set attributeName="href" to="javascript:alert('SET_XSS')"></set>
<text y="30">Click set</text>
</a>
</svg>
Ammonia did not apply attribute filters based on attributeName,
so the contents of the to, from, and values tags were not sanitized as URLs.
Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default.
Discovered by: Younghun Ko (@koyokr)
References
| URL | Type | |
|---|---|---|
{
"affected": [
{
"database_specific": {
"categories": [
"format-injection"
],
"cvss": null,
"informational": null
},
"ecosystem_specific": {
"affected_functions": null,
"affects": {
"arch": [],
"functions": [],
"os": []
}
},
"package": {
"ecosystem": "crates.io",
"name": "ammonia",
"purl": "pkg:cargo/ammonia"
},
"ranges": [
{
"events": [
{
"introduced": "0.0.0-0"
},
{
"fixed": "3.3.3"
},
{
"introduced": "4.0.0"
},
{
"fixed": "4.0.3"
},
{
"introduced": "4.1.0"
},
{
"fixed": "4.1.4"
}
],
"type": "SEMVER"
}
],
"versions": []
}
],
"aliases": [
"CVE-2026-102342",
"GHSA-m6mh-2hw2-555x"
],
"database_specific": {
"license": "CC0-1.0"
},
"details": "The following SVG will produce a link with a javascript scheme.\nIf the user clicks this link, they will run it.\n\n```xml\n\u003csvg xmlns=\"http://www.w3.org/2000/svg\"\u003e\n \u003ca\u003e\n \u003cset attributeName=\"href\" to=\"javascript:alert(\u0027SET_XSS\u0027)\"\u003e\u003c/set\u003e\n \u003ctext y=\"30\"\u003eClick set\u003c/text\u003e\n \u003c/a\u003e\n\u003c/svg\u003e\n```\n\nAmmonia did not apply attribute filters based on `attributeName`,\nso the contents of the `to`, `from`, and `values` tags were not sanitized as URLs.\n\nApplications that do not explicitly allow either of these tags should not be affected,\nsince neither are allowed by default.\n\n---\n\n**Discovered by:** [Younghun Ko (@koyokr)](https://github.com/koyokr)",
"id": "RUSTSEC-2026-0213",
"modified": "2026-09-30T07:15:39Z",
"published": "2026-07-21T12:00:00Z",
"references": [
{
"type": "PACKAGE",
"url": "https://crates.io/crates/ammonia"
},
{
"type": "ADVISORY",
"url": "https://rustsec.org/advisories/RUSTSEC-2026-0213.html"
}
],
"related": [],
"severity": [],
"summary": "XSS in ammonia via SVG `animate` and `set` animation tags"
}