Vulnerability GHSA-m6mh-2hw2-555x

Medium Risk
MEDIUM RISK
CVSS Score: 5.4
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 hours ago
September 29, 2026 at 11:09 PM UTC
Ammonia: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
0.1.0 - 0.7.0 and 1.0.0 - 3.3.2 and 4.0.0 - 4.0.2 and 4.1.2 - 4.1.3
0.1.0 - 0.7.0 and 1.0.0 - 3.3.2 and 4.0.0 - 4.0.2 and 4.1.2 - 4.1.3

Summary

Ammonia: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Details

The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.

<svg xmlns="http://www.w3.org/2000/svg">
  <a>
    <set attributeName="href" to="javascript:alert('SET_XSS')"></set>
    <text y="30">Click set</text>
  </a>
</svg>

Impact

Allows stored XSS in applications that allow the animate and set tags.

Patches

Fixed in 3.3.3, 4.0.3, and 4.1.4

Workarounds

Do not enable the animate or set tags.

Impacted packages

Timeline

Published
2 hours ago
September 29, 2026 at 11:09 PM UTC
Fixed (3.3.3)
2 months ago
July 22, 2026 at 03:45 AM UTC
Fixed (4.0.3)
2 months ago
July 22, 2026 at 03:46 AM UTC
Fixed (4.1.4)
2 months ago
July 22, 2026 at 03:48 AM UTC
Last Modified
1 hour ago
September 29, 2026 at 11:15 PM UTC