PT-2026-102975 · Ammonia · Ammonia
CVE-2026-102342
·
Published
2026-07-21
·
Updated
2026-09-29
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Ammonia versions prior to 3.3.3
Ammonia versions prior to 4.0.3
Ammonia versions prior to 4.1.4
Description
Ammonia fails to apply attribute filters based on the
attributeName variable, which allows the contents of the to, from, and values tags to bypass URL sanitization. This can lead to stored Cross-Site Scripting (XSS), where an attacker can inject a javascript scheme into an SVG link. If a user clicks the link, the malicious script will execute. This issue specifically affects applications that explicitly enable the animate and set tags.Recommendations
Update to version 3.3.3.
Update to version 4.0.3.
Update to version 4.1.4.
Do not enable the
animate or set tags.Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ammonia