RUSTSEC-2025-0071
Incorrect handling of embedded SVG and MathML leads to mutation XSS after removal
Details
Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML.
This vulnerability only has an effect when the `svg` or `math` tag is allowed, because it relies on a tag being parsed as html during the cleaning process, but serialized in a way that causes in to be parsed as xml by the browser.
Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These [elements] are:
* title * textarea * xmp * iframe * noembed * noframes * plaintext * noscript * style * script
Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default.
[elements]: https://github.com/servo/html5ever/blob/57eb334c0ffccc6f88d563419f0fbeef6ff5741c/html5ever/src/tree_builder/rules.rs
Are you affected?
Enter the version of the package you're using.
Affected packages
0.0.0-0Fixed in: 3.3.1Upgrade ammonia to 3.3.1 or newer (ecosystem crates.io).