AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-102342.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Sep 29, 2026

Disclosure summary

The following SVG will produce a link with a `javascript` scheme. If the user clicks this link, they will run it. ```svg Click set ``` ### Impact Allows stored XSS in applications that allow the `animate` and `set` tags. ### Patches Fixed in 3.3.3, 4.0.3, and 4.1.4 ### Workarounds Do not enable the `animate` or `set` tags.

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-m6mh-2hw2-555x

Open original source · Updated Sep 29, 2026

Ammonia: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Source severity: MEDIUM / 0

EcosystemPackageAffected rangeFirst patched
rustammonia< 3.3.23.3.3
rustammonia>= 4.0.0,4.0.3
rustammonia>= 4.1.2,4.1.4

Original records & references

PUBLISHED 2026-09-29T19:09:16-04:00
MODIFIED 2026-09-29T19:09:17-04:00
INGESTED 2026-10-06T11:43:08-04:00