Ammonia, Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’), GHSA-m6mh-2hw2-555x (Moderate) -DC-Sep2026-2633

Listen to this Post

The ammonia crate is a popular HTML sanitization library written in Rust. It is designed to remove potentially dangerous HTML content while allowing safe markup. The vulnerability arises from improper neutralization of input during web page generation, specifically within the handling of SVG animation elements. When the `animate` and `set` tags are enabled in the sanitizer configuration, ammonia fails to apply attribute filters based on the `attributeName` property. This means that the contents of the to, from, and `values` attributes of these tags are not sanitized as URLs. An attacker can craft an SVG containing a `` element that sets the `href` attribute of an `` element to a `javascript:` scheme. When a user clicks the resulting link, the embedded JavaScript code executes in the context of the victim’s browser. This constitutes a stored cross-site scripting (XSS) vulnerability. The issue affects applications that explicitly allow the `animate` or `set` tags, as neither is permitted by default. The vulnerability has been assigned the identifier GHSA-m6mh-2hw2-555x and is rated as moderate severity. Affected versions include those before 3.3.2, versions 4.0.0 through 4.0.2, and versions 4.1.2 through 4.1.3. Patches are available in versions 3.3.3, 4.0.3, and 4.1.4. The advisory was published on July 21, 2026, and last updated on September 29, 2026. The vulnerability was discovered by Younghun Ko (@koyokr). As a workaround, applications should avoid enabling the `animate` or `set` tags in their ammonia configuration. This issue highlights the importance of thoroughly sanitizing all attributes that can influence URL schemes, especially in dynamic contexts like SVG animations.

DailyCVE Form:

Platform: Rust ammonia crate
Version: multiple affected ranges
Vulnerability: SVG XSS
Severity: Moderate
date: 2026-07-21

Prediction: Patched 2026-09-29

What Undercode Say:

Check dependency:

cargo tree -i ammonia

Verify version:

cargo metadata --format-version 1 | grep ammonia

Test sanitization:

use ammonia::Builder;
let input = r"<svg><a><set attributeName="href" to="javascript:alert(1)"></set><text>Click</text></a></svg>";
let output = Builder::default().add_tags(&["svg", "a", "set", "text"]).clean(input).to_string();
println!("{}", output);

Exploit: (Educational Purposes!)


<svg xmlns="http://www.w3.org/2000/svg">
<a>
<set attributeName="href" to="javascript:alert('SET_XSS')"></set>
<text y="30">Click set</text>
</a>
</svg>

Protection:

Update to ammonia 3.3.3, 4.0.3, or 4.1.4. Disable `animate` and `set` tags if not required. Validate all SVG attributes that accept URLs.

Impact:

Stored XSS in applications allowing `animate` or `set` tags. Session hijacking, data theft, and arbitrary JavaScript execution in the victim’s browser.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top