Vulnerability GHSA-m6mh-2hw2-555x
Medium Risk
MEDIUM RISK
CVSS Score: 5.4
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
2 hours ago
September 29, 2026 at 11:09 PM UTC
Ammonia: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
0.1.0 - 0.7.0 and 1.0.0 - 3.3.2 and 4.0.0 - 4.0.2 and 4.1.2 - 4.1.3
0.1.0 - 0.7.0 and 1.0.0 - 3.3.2 and 4.0.0 - 4.0.2 and 4.1.2 - 4.1.3
Summary
Ammonia: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Details
The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
<svg xmlns="http://www.w3.org/2000/svg">
<a>
<set attributeName="href" to="javascript:alert('SET_XSS')"></set>
<text y="30">Click set</text>
</a>
</svg>
Impact
Allows stored XSS in applications that allow the animate and set tags.
Patches
Fixed in 3.3.3, 4.0.3, and 4.1.4
Workarounds
Do not enable the animate or set tags.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
2 months ago
XSS in ammonia via SVG `animate` and `set` animation tags
0.1.0 - 0.7.0 and 1.0.0 - 3.3.2 RUSTSEC-2026-0213
0.1.0 - 0.7.0 and 1.0.0 - 3.3.2 RUSTSEC-2026-0213
Unknown
3 months ago
mXSS in ammonia via MathML `annotation-xml` encoding strip
0.1.0 - 0.7.0 and 1.0.0 - 3.3.1 RUSTSEC-2026-0193
0.1.0 - 0.7.0 and 1.0.0 - 3.3.1 RUSTSEC-2026-0193
Low Risk
1 year ago
Ammonia incorrectly handles embedded SVG and MathML leading to mutation XSS after removal
0.1.0 - 0.7.0 and 1.0.0 - 3.3.0 and 4.0.0 and 4.1.0 - 4.1.1 GHSA-mm7x-qfjj-5g2c
0.1.0 - 0.7.0 and 1.0.0 - 3.3.0 and 4.0.0 and 4.1.0 - 4.1.1 GHSA-mm7x-qfjj-5g2c
Unknown
1 year ago
Incorrect handling of embedded SVG and MathML leads to mutation XSS after removal
0.1.0 - 0.7.0 and 1.0.0 - 3.3.0 RUSTSEC-2025-0071
0.1.0 - 0.7.0 and 1.0.0 - 3.3.0 RUSTSEC-2025-0071
Medium Risk
4 years ago
Space bug in `clean_text`
3.0.0 - 3.1.2 GHSA-p2g9-94wh-65c2
3.0.0 - 3.1.2 GHSA-p2g9-94wh-65c2
Impacted packages
Timeline
Published
2 hours ago
September 29, 2026 at 11:09 PM UTC
Fixed (3.3.3)
2 months ago
July 22, 2026 at 03:45 AM UTC
Fixed (4.0.3)
2 months ago
July 22, 2026 at 03:46 AM UTC
Fixed (4.1.4)
2 months ago
July 22, 2026 at 03:48 AM UTC
Last Modified
1 hour ago
September 29, 2026 at 11:15 PM UTC