CVE-2026-73492 | flavorjones Loofah up to 2.25.1 HTML5 Scrub Scrub.allowed_uri HTML injection

SecurityVulns

A vulnerability classified as problematic has been found in flavorjones Loofah up to 2.25.1. The impacted element is the function Loofah::HTML5::Scrub.allowed_uri of the component HTML5 Scrub. The manipulation leads to HTML injection.

This vulnerability is uniquely identified as CVE-2026-73492. The attack is possible to be carried out remotely. No exploit exists.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More