CVE-2026-73491Low· 2.3▾ SunlitLoofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: URIs whose scheme is split …
▾ Sunlit zone — Low / medium · no exploitation signal
impact 12.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake. The CVSS score shown above comes from the assigning CNA record, not NVD.
Exploit-prediction probability, daily snapshots since Sep 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.2%
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. From 2.25.0 until 2.25.2, Loofah::HTML5::Scrub.allowed_uri? does not reject javascript: URIs whose scheme is split or prefixed with the HTML5 named whitespace character references or . CGI.unescapeHTML leaves those references intact, so allowed_uri? reports the URL safe even though a browser decodes and strips the tab or line feed and executes the resulting javascript: URL. This issue affects only callers that pass HTML-encoded strings directly to allowed_uri?; Loofah's default sanitize() path is not affected. This issue is fixed in version 2.25.2.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
GHSA-8whx-365g-h9vvLowLoofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references
GHSA-5qhf-9phg-95m2LowLoofah `allowed_uri?` does not detect `javascript:` URIs split by numeric character references without semicolons
GHSA-9wjq-cp2p-hrgfMedium· 4.7Loofah: SVG `href` attribute bypasses local-reference restriction
CVE-2026-73492NoneLoofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri
CVE-2026-61788High· 7.4DBHub is a database MCP server for Postgres, MySQL, SQL Server, Oracle, MariaDB, SQLite
CVE-2026-44114High· 7.8OpenClaw < 2026.4.20 - Environment Variable Namespace Collision via Workspace dotenv