RUSTSEC-2026-0213
XSS in ammonia via SVG `animate` and `set` animation tags
Details
The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.
```xml <svg xmlns="http://www.w3.org/2000/svg"> <a> <set attributeName="href" to="javascript:alert('SET_XSS')"></set> <text y="30">Click set</text> </a> </svg> ```
Ammonia did not apply attribute filters based on `attributeName`, so the contents of the `to`, `from`, and `values` tags were not sanitized as URLs.
Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default.
---
**Discovered by:** [Younghun Ko (@koyokr)](https://github.com/koyokr)
Are you affected?
Enter the version of the package you're using.
Affected packages
0.0.0-0 Fixed in: 3.3.3 Upgrade ammonia to 3.3.3 or newer (ecosystem crates.io).
References
- https://crates.io/crates/ammonia [PACKAGE]
- https://rustsec.org/advisories/RUSTSEC-2026-0213.html [ADVISORY]