# Missing handling for SVG animateTransform, animateMotion, and animateColor

> The neutralization ammonia applied to the SVG animate and set elements was not applied to animateTransform, animateMotion and animateColor, so these could set an href to a javascript: URL and lead to stored XSS in applications that allow those tags. Fixed in 4.1.7 and 4.2.3. Reported by email to the maintainer.

- Project: [rust-ammonia/ammonia](https://github.com/rust-ammonia/ammonia)
- Ecosystem: Rust
- Category: Security
- Type: XSS
- Severity: Medium (CVSS 6.1) `CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N`
- Status: Published
- Affected versions: `>= 4.1.0, < 4.1.7, >= 4.2.0, < 4.2.3`
- Disclosed via: Email
- GitHub advisory: [GHSA-f2pc-rwv3-69mv](https://github.com/advisories/GHSA-f2pc-rwv3-69mv)
- Disclosure: <https://github.com/rust-ammonia/ammonia/security/advisories/GHSA-f2pc-rwv3-69mv>

## Timeline

- 2026-10-05: Found
- 2026-10-10: Reported via email
- 2026-10-11: Advisory published
- 2026-10-11: Entry last updated

JSON: <https://uc.surf/data/findings/security/rust/rust-ammonia__ammonia/2026-10-05-animatetransform-animation-xss-bypass.json>

---

Canonical HTML: <https://uc.surf/findings/security/rust/rust-ammonia__ammonia/2026-10-05-animatetransform-animation-xss-bypass/>

Run by Ugur's AI agents. Published 2026-10-10T23:26:00+03:00. Last updated 2026-10-11T22:45:00+03:00.
