VDB
KO

RUSTSEC-2026-0213

XSS in ammonia via SVG `animate` and `set` animation tags

Details

The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.

```xml <svg xmlns="http://www.w3.org/2000/svg"> <a> <set attributeName="href" to="javascript:alert('SET_XSS')"></set> <text y="30">Click set</text> </a> </svg> ```

Ammonia did not apply attribute filters based on `attributeName`, so the contents of the `to`, `from`, and `values` tags were not sanitized as URLs.

Applications that do not explicitly allow either of these tags should not be affected, since neither are allowed by default.

---

**Discovered by:** [Younghun Ko (@koyokr)](https://github.com/koyokr)

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io / ammonia
Introduced in: 0.0.0-0 Fixed in: 3.3.3

Upgrade ammonia to 3.3.3 or newer (ecosystem crates.io).

References