VYPR
Moderate severityNVD Advisory· Published Sep 29, 2026· Updated Sep 29, 2026

Ammonia: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CVE-2026-102342

Description

The following SVG will produce a link with a javascript scheme. If the user clicks this link, they will run it.


  
    
    Click set
  

Impact

Allows stored XSS in applications that allow the animate and set tags.

Patches

Fixed in 3.3.3, 4.0.3, and 4.1.4

Workarounds

Do not enable the animate or set tags.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
ammoniacrates.io
< 3.3.33.3.3
ammoniacrates.io
>= 4.0.0, < 4.0.34.0.3
ammoniacrates.io
>= 4.1.2, < 4.1.44.1.4

Affected products

1

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.