VDB
Sign up
—

RUSTSEC-2025-0071

Incorrect handling of embedded SVG and MathML leads to mutation XSS after removal

Details

Affected versions of this crate did not correctly strip namespace-incompatible tags in certain situations, causing it to incorrectly account for differences between HTML, SVG, and MathML.

This vulnerability only has an effect when the `svg` or `math` tag is allowed, because it relies on a tag being parsed as html during the cleaning process, but serialized in a way that causes in to be parsed as xml by the browser.

Additionally, the application using this library must allow a tag that is parsed as raw text in HTML. These [elements] are:

* title * textarea * xmp * iframe * noembed * noframes * plaintext * noscript * style * script

Applications that do not explicitly allow any of these tags should not be affected, since none are allowed by default.

[elements]: https://github.com/servo/html5ever/blob/57eb334c0ffccc6f88d563419f0fbeef6ff5741c/html5ever/src/tree_builder/rules.rs

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/ammonia
Introduced in: 0.0.0-0Fixed in: 3.3.1

Upgrade ammonia to 3.3.1 or newer (ecosystem crates.io).

References