CVE-2026-102342Medium· 5.4▾ SunlitAmmonia: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
▾ Sunlit zone — Low / medium · no exploitation signal
impact 29.7 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
<svg xmlns="http://www.w3.org/2000/svg">
<a>
<set attributeName="href" to="javascript:alert('SET_XSS')"></set>
<text y="30">Click set</text>
</a>
</svg>
Allows stored XSS in applications that allow the animate and set tags.
Fixed in 3.3.3, 4.0.3, and 4.1.4
Do not enable the animate or set tags.
ammonia < 3.3.2ammonia >= 4.0.0, <= 4.0.2ammonia >= 4.1.2, <= 4.1.3Upgrade to a patched release:
ammonia 3.3.3ammonia 4.0.3ammonia 4.1.4Connected by shared product, vendor, weakness, or advisory.
RUSTSEC-2026-0213NoneXSS in ammonia via SVG `animate` and `set` animation tags
CVE-2026-63430NonemXSS in ammonia via MathML `annotation-xml` encoding strip
CVE-2021-41164High· 8.2CKEditor4 is an open source WYSIWYG HTML editor
CVE-2021-41184Medium· 6.5jQuery-UI is the official jQuery user interface library
CVE-2021-41183Medium· 6.5jQuery-UI is the official jQuery user interface library
CVE-2021-41182Medium· 6.5jQuery-UI is the official jQuery user interface library