Vulnerability RUSTSEC-2026-0193

Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
3 months ago
June 30, 2026 at 12:00 PM UTC
mXSS in ammonia via MathML `annotation-xml` encoding strip
0.1.0 - 0.7.0 and 1.0.0 - 3.3.1
0.1.0 - 0.7.0 and 1.0.0 - 3.3.1

Summary

mXSS in ammonia via MathML `annotation-xml` encoding strip

Details

If a certain set of MathML tags are enabled, an attacker can inject arbitrary JavaScript code into the user's browser.

The annotation-xml tag has slightly different behavior than the other "integration point" tags in MathML and SVG, but ammonia didn't handle it, so it didn't correctly strip the namespace-incompatible tags.

This vulnerability only has an effect when the math and annotation-xml tags are both enabled, but the encoding attribute is disabled, because it relies on the following sequence of steps:

  1. User writes code like <math><annotation-xml encoding="text/html"><gadget></annotation-xml></math>.
  2. Namespace filtering checks the DOM, and it passes. <gadget> is parsed as HTML.
  3. Attribute filter strips it down to <math><annotation-xml><gadget></annotation-xml></math>. Because the encoding attribute is gone, <gadget> is now parsed as MathML.
  4. The gadget is written in such a way that it exploits the parsing differences between HTML and MathML.

Additionally, the gadget can only be written using a tag that is parsed as raw text in HTML. These elements are:

  • title
  • textarea
  • xmp
  • iframe
  • noembed
  • noframes
  • plaintext
  • noscript
  • style
  • script

Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default.

Impacted packages

Timeline

Published
3 months ago
June 30, 2026 at 12:00 PM UTC
Fixed (3.3.2)
3 months ago
June 30, 2026 at 07:36 AM UTC
Fixed (4.0.2)
3 months ago
June 30, 2026 at 07:39 AM UTC
Fixed (4.1.3)
3 months ago
June 30, 2026 at 07:48 AM UTC
Last Modified
2 months ago
July 17, 2026 at 05:41 AM UTC