{"id":"CVE-2026-102342","aliases":["GHSA-m6mh-2hw2-555x"],"title":"Ammonia: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","summary":"Ammonia: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","severity":"medium","cvss":5.4,"cwe":["CWE-79"],"vendor":"ammonia","product":"ammonia","ecosystem":"rust","affected":["ammonia < 3.3.2","ammonia >= 4.0.0, <= 4.0.2","ammonia >= 4.1.2, <= 4.1.3"],"patched":["ammonia 3.3.3","ammonia 4.0.3","ammonia 4.1.4"],"published":"2026-09-29","updated":"2026-09-29","sourceUpdated":"2026-09-29T23:09:17Z","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-m6mh-2hw2-555x","references":[{"url":"https://github.com/rust-ammonia/ammonia/security/advisories/GHSA-m6mh-2hw2-555x"},{"url":"https://github.com/rust-ammonia/ammonia/pull/250"},{"url":"https://github.com/rust-ammonia/ammonia/pull/251"},{"url":"https://github.com/rust-ammonia/ammonia/pull/252"},{"url":"https://github.com/rust-ammonia/ammonia/commit/9394bd81179e756cb911314deabd943f1a9c8989"},{"url":"https://github.com/rust-ammonia/ammonia/commit/9e3335e2dd8ab07346ff7997f20662a3da4023f6"},{"url":"https://github.com/rust-ammonia/ammonia/commit/d2ae1547f478bd84d158bc5e57f5d31437dc4d8d"},{"url":"https://rustsec.org/advisories/RUSTSEC-2026-0213.html"},{"url":"https://github.com/advisories/GHSA-m6mh-2hw2-555x"}],"tags":["ghsa","rust"],"ingestedAt":"2026-09-29T23:52:50.543Z","slug":"CVE-2026-102342","body":"## Overview\n\nThe following SVG will produce a link with a `javascript` scheme. If the user clicks this link, they will run it.\n\n```svg\n<svg xmlns=\"http://www.w3.org/2000/svg\">\n  <a>\n    <set attributeName=\"href\" to=\"javascript:alert('SET_XSS')\"></set>\n    <text y=\"30\">Click set</text>\n  </a>\n</svg>\n```\n\n### Impact\n\nAllows stored XSS in applications that allow the `animate` and `set` tags.\n\n### Patches\n\nFixed in 3.3.3, 4.0.3, and 4.1.4\n\n### Workarounds\n\nDo not enable the `animate` or `set` tags.\n\n## Affected packages\n\n- `ammonia < 3.3.2`\n- `ammonia >= 4.0.0, <= 4.0.2`\n- `ammonia >= 4.1.2, <= 4.1.3`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `ammonia 3.3.3`\n- `ammonia 4.0.3`\n- `ammonia 4.1.4`","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":29.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}