GHSA-m6mh-2hw2-555x

Suggest an improvement
Source
https://github.com/advisories/GHSA-m6mh-2hw2-555x
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-m6mh-2hw2-555x/GHSA-m6mh-2hw2-555x.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-m6mh-2hw2-555x
Aliases
Published
2026-09-29T23:09:16Z
Modified
2026-09-29T23:25:38Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Ammonia: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Details

The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.

<svg xmlns="http://www.w3.org/2000/svg">
  <a>
    <set attributeName="href" to="javascript:alert('SET_XSS')"></set>
    <text y="30">Click set</text>
  </a>
</svg>

Impact

Allows stored XSS in applications that allow the animate and set tags.

Patches

Fixed in 3.3.3, 4.0.3, and 4.1.4

Workarounds

Do not enable the animate or set tags.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-29T23:09:16Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
}
References

Affected packages

crates.io / ammonia

Package

Name
ammonia
View open source insights on deps.dev
Purl
pkg:cargo/ammonia

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.3.3

Database specific

last_known_affected_version_range
"< 3.3.2"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-m6mh-2hw2-555x/GHSA-m6mh-2hw2-555x.json"

crates.io / ammonia

Package

Name
ammonia
View open source insights on deps.dev
Purl
pkg:cargo/ammonia

Affected ranges

Type
SEMVER
Events
Introduced
4.0.0
Fixed
4.0.3

Database specific

last_known_affected_version_range
"<= 4.0.2"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-m6mh-2hw2-555x/GHSA-m6mh-2hw2-555x.json"

crates.io / ammonia

Package

Name
ammonia
View open source insights on deps.dev
Purl
pkg:cargo/ammonia

Affected ranges

Type
SEMVER
Events
Introduced
4.1.2
Fixed
4.1.4

Database specific

last_known_affected_version_range
"<= 4.1.3"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-m6mh-2hw2-555x/GHSA-m6mh-2hw2-555x.json"