GEM · JULY 2026 · EARLY WARNING

Loofah Gem Vulnerability: Potential XSS Risk Under Investigation

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-46FP-8F5P-PF2MGHSA-8WHX-365G-H9VVSeverity: HIGH

An early warning has been issued regarding a potential vulnerability in the Loofah gem, where the allowed_uri? method may fail to detect javascript: URIs when the scheme is split by named whitespace character references, potentially leading to cross-site scripting (XSS) vulnerabilities.

What happened

Reports indicate that the Loofah gem's allowed_uri? method does not correctly identify javascript: URIs when the scheme is divided using named whitespace character references. This oversight could allow malicious scripts to be executed, leading to XSS attacks. The vulnerability appears to affect multiple versions of the Loofah gem, with fixes available in versions 2.19.1 and 2.25.1. Users of the Loofah gem are advised to review their current version and upgrade to a secure version if necessary. For detailed version information and to assess your exposure, consult the primary sources provided.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If loofah is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats