Executive brief
Loofah is a Ruby library used to clean and sanitize HTML and SVG content to prevent security risks. A vulnerability was found where the sanitizer failed to block external references in SVG images when using the 'href' attribute, even though it correctly blocked them in the older 'xlink:href' format. This could allow an attacker to track users or potentially execute malicious scripts if a user views a specially crafted image.
Technical details
Loofah's HTML5 sanitizer implementation only restricted the 'xlink:href' attribute on certain SVG elements to local, same-document references. Because the SVG 2 specification introduced the plain 'href' attribute as a replacement for the deprecated 'xlink:href', browsers accept both; however, Loofah did not apply the same security restrictions to the 'href' attribute. An attacker can use SVG tags like <use> or <feImage> with an external 'href' to load remote content. If the referenced content is same-origin and contains scripts, it may lead to XSS. Cross-origin fetches are partially mitigated by modern browser security policies but still pose a risk for tracking or information disclosure. The issue is fixed in version 2.25.2.
Affected products
- flavorjones loofah < 2.25.2
Timeline
- 2026-07-15: disclosed: Vulnerability found by maintainer during audit.
- 2026-07-15: patched: Version 2.25.2 released.
- 2026-07-21: advisory: GitHub Advisory published.