Vulnerability RUSTSEC-2025-0071

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
1 year ago
September 21, 2025 at 12:00 PM UTC
Incorrect handling of embedded SVG and MathML leads to mutation XSS after removal
0.1.0 - 0.7.0 and 1.0.0 - 3.3.0
0.1.0 - 0.7.0 and 1.0.0 - 3.3.0

Summary

Incorrect handling of embedded SVG and MathML leads to mutation XSS after removal

Details

Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML.

This vulnerability only has an effect when the svg or math tag is allowed, because it relies on a tag being parsed as html during the cleaning process, but serialized in a way that causes in to be parsed as xml by the browser.

Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These elements are:

  • title
  • textarea
  • xmp
  • iframe
  • noembed
  • noframes
  • plaintext
  • noscript
  • style
  • script

Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default.

Impacted packages

Timeline

Published
1 year ago
September 21, 2025 at 12:00 PM UTC
Fixed (4.1.2)
1 year ago
September 22, 2025 at 12:56 AM UTC
Fixed (4.0.1)
1 year ago
September 22, 2025 at 01:08 AM UTC
Fixed (3.3.1)
1 year ago
September 22, 2025 at 01:14 AM UTC
Last Modified
11 months ago
October 28, 2025 at 06:29 AM UTC