You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Cross-site Scripting in loofah
Moderate severity
GitHub Reviewed
Published
Mar 21, 2018
to the GitHub Advisory Database
•
Updated Jul 5, 2023
Loofah allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments.
Users are affected if running Loofah < 2.2.1, but only:
JRuby users are not affected.
References