Loofah Gem Vulnerability: Potential XSS Risk Under Investigation
An early warning has been issued regarding a potential vulnerability in the Loofah gem, where the allowed_uri? method may fail to detect javascript: URIs when the scheme is split by named whitespace character references, potentially leading to cross-site scripting (XSS) vulnerabilities.
What happened
Reports indicate that the Loofah gem's allowed_uri? method does not correctly identify javascript: URIs when the scheme is divided using named whitespace character references. This oversight could allow malicious scripts to be executed, leading to XSS attacks. The vulnerability appears to affect multiple versions of the Loofah gem, with fixes available in versions 2.19.1 and 2.25.1. Users of the Loofah gem are advised to review their current version and upgrade to a secure version if necessary. For detailed version information and to assess your exposure, consult the primary sources provided.
How 0Day mitigates this
loofah is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.