PT-2026-102975 · Ammonia · Ammonia

CVE-2026-102342

·

Published

2026-07-21

·

Updated

2026-09-29

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ammonia versions prior to 3.3.3 Ammonia versions prior to 4.0.3 Ammonia versions prior to 4.1.4
Description Ammonia fails to apply attribute filters based on the attributeName variable, which allows the contents of the to, from, and values tags to bypass URL sanitization. This can lead to stored Cross-Site Scripting (XSS), where an attacker can inject a javascript scheme into an SVG link. If a user clicks the link, the malicious script will execute. This issue specifically affects applications that explicitly enable the animate and set tags.
Recommendations Update to version 3.3.3. Update to version 4.0.3. Update to version 4.1.4. Do not enable the animate or set tags.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-102342
GHSA-M6MH-2HW2-555X
RUSTSEC-2026-0213

Affected Products

Ammonia