Executive brief
Loofah is a Ruby library used to sanitize and scrub HTML to prevent security vulnerabilities. A flaw in its URI validation helper allows specially crafted 'javascript:' links to bypass security checks if they use specific HTML5 named characters like tab or newline. If an application uses this helper to validate user-provided links, an attacker could inject malicious scripts that execute in a victim's browser, leading to account takeover or data theft.
Technical details
The `Loofah::HTML5::Scrub.allowed_uri?` method uses `CGI.unescapeHTML` to decode entities before checking the URI scheme. However, `CGI.unescapeHTML` does not support HTML5 named character references such as `	` (U+0009) and `
` (U+000A). While Loofah fails to decode and identify these as part of a `javascript:` protocol, web browsers following the WHATWG URL specification will decode and strip these whitespace characters, executing the underlying script. This vulnerability specifically affects direct callers of the `allowed_uri?` helper; the default `sanitize()` path is unaffected as it utilizes Nokogiri's parser which correctly handles these entities. A fix is available in version 2.25.2.
Affected products
- flavorjones loofah >= 2.25.0, < 2.25.2
Timeline
- 2026-07-15: disclosed
- 2026-07-15: patched: Fixed in version 2.25.2
- 2026-07-21: advisory