ammonia is vulnerable to Cross-Site Scripting (XSS)
54
Medium Risk
The ammonia HTML sanitizer applies attribute filters to SVG elements but did not sanitize values based on the attributeName referenced by SVG animate and set tags. Untrusted markup such as <set attributeName="href" to="javascript:alert('SET_XSS')"> inside an allowed <a> element can inject a javascript: URL that executes when a victim clicks the resulting link. The fix applies URL sanitization to to, from, and values content according to the targeted attribute name.
You are affected if you are using a version that falls within the vulnerable range and your sanitizer configuration explicitly allows the SVG animate or set tags, which are disabled by default.
ammonia is vulnerable to Cross-Site Scripting (XSS) in versions 3.2.0 - 3.3.2, 4.0.0 - 4.0.2 and 4.1.0 - 4.1.3.
Upgrade the ammonia library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant