GHSA-8whx-365g-h9vv

    Dashboard / Vulnerabilities / GHSA-8whx-365g-h9vv

    GHSA-8whx-365g-h9vv

    Published: 21 Jul 2026Last Modified: 10 Sept 2026

    Summary: Loofah `allowed_uri?` does not detect `javascript:` URIs split by named whitespace character references

    Details: ## Summary `Loofah::HTML5::Scrub.allowed_uri?` does not correctly reject `javascript:` URIs when the scheme is split or prefixed by the HTML5 named character references `	` (tab) or `
` (line feed). This is a bypass of the fix for [GHSA-46fp-8f5p-pf2m](https://github.com/flavorjones/loofah/security/advisories/GHSA-46fp-8f5p-pf2m), which handled the equivalent numeric character references (`	`, `
`, `
`) but did not cover the named forms. ## Details `allowed_uri?` decodes HTML entities with `CGI.unescapeHTML`, which handles numeric character references but not HTML5 named character references. Payloads like `java	script:alert(1)` are therefore left intact, so the method does not recognize the `javascript:` scheme and returns `true`. A browser, however, decodes `	` and `
` to tab and line feed and strips them from the URL during parsing, producing `javascript:alert(1)`. `	` and `
` are the only relevant named character references: across the HTML5 named-character table, they are the only two that decode to characters the WHATWG URL parser strips from a URL (U+0009 and U+000A; there is no named reference for U+000D). ` ` / ` ` decode to U+00A0, which browsers do not strip, so they aren't usable for this bypass. Note that Loofah's default `sanitize()` path is **not** affected, because Nokogiri decodes or entity-escapes HTML entities during parsing before Loofah evaluates the URI protocol. This issue only affects callers of the public `allowed_uri?` string-level helper that pass it HTML-encoded strings. ## Impact Callers that validate a user-controlled URL with `Loofah::HTML5::Scrub.allowed_uri?` and then render the approved value into an `href` or other browser-interpreted URI attribute may be vulnerable to cross-site scripting (XSS). This includes applications that call `allowed_uri?` directly, as well as higher-level features built on top of it, such as Action Text 8.2's markdown link validation. ## Mitigation Upgrade to Loofah >= 2.25.2. ## Credit Responsibly reported by GitHub user @connorshea.

    Affected packages

    Package

    Name: loofah

    Purl: pkg:gem/loofah

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 2.25.0
    Fixed -2.25.2

    Affected versions

    2.25.0
    2.25.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-8whx-365g-h9vv | CVE-DB