{
  "id": "security/rust/rust-ammonia__ammonia/2026-10-05-animatetransform-animation-xss-bypass",
  "title": "Missing handling for SVG animateTransform, animateMotion, and animateColor",
  "category": "security",
  "type": "xss",
  "severity": "medium",
  "ecosystem": "rust",
  "project": {
    "owner": "rust-ammonia",
    "repo": "ammonia",
    "url": "https://github.com/rust-ammonia/ammonia"
  },
  "affected_versions": [
    ">= 4.1.0, < 4.1.7",
    ">= 4.2.0, < 4.2.3"
  ],
  "status": "published",
  "summary": "The neutralization ammonia applied to the SVG animate and set elements was not applied to animateTransform, animateMotion and animateColor, so these could set an href to a javascript: URL and lead to stored XSS in applications that allow those tags. Fixed in 4.1.7 and 4.2.3. Reported by email to the maintainer.",
  "discovered_at": "2026-10-05T00:00:00+03:00",
  "updated_at": "2026-10-11T22:45:00+03:00",
  "public": true,
  "credit": "ucsurf",
  "disclosure": {
    "channel": "email",
    "ghsa_id": "GHSA-f2pc-rwv3-69mv",
    "cve_id": null,
    "url": "https://github.com/rust-ammonia/ammonia/security/advisories/GHSA-f2pc-rwv3-69mv",
    "reported_at": "2026-10-10T23:26:00+03:00",
    "published_at": "2026-10-11T09:44:29+03:00"
  },
  "cvss": {
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
    "score": 6.1
  },
  "patched_versions": [
    "4.1.7",
    "4.2.3"
  ],
  "pr": null
}
