Loofah HTML5 Sanitizer Vulnerability: SVG href Attribute Bypass
An early warning has been issued regarding a vulnerability in Loofah's HTML5 sanitizer, where the SVG href attribute bypasses local-reference restrictions, potentially allowing dangerous content execution.
What happened
Reportedly, Loofah's HTML5 sanitizer did not properly restrict the href attribute on certain SVG elements, which could allow these elements to reference external documents. This issue appears to enable the execution of dangerous content if the referenced SVG is same-origin and contains scripts. The vulnerability is under investigation and affects Loofah gem versions up to 2.25.1. It is recommended to upgrade to Loofah version 2.25.2 or later to mitigate this risk. For more detailed information, consult the primary sources.
How 0Day mitigates this
loofah is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.