Mike Dalessio Loofah是Mike Dalessio个人开发者开源的一款HTML文档处理组件。 Mike Dalessio Loofah 2.25.0版本至2.25.2之前版本存在安全漏洞,该漏洞源于Loofah::HTML5::Scrub.allowed_uri?对URI校验不充分,未能拒绝方案被数字字符引用分割的javascript:或vbscript: URI,可能导致跨站脚本攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| flavorjones | loofah | >= 2.25.0, < 2.25.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| flavorjones | loofah | >= 2.25.0, < 2.25.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-73490 | 4.7 MEDIUM | Loofah: SVG `href` attribute bypasses local-reference restriction |
| CVE-2026-73491 | 2.3 LOW | Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace charact |
No comments yet