CVE-2026-73490 | Flavorjones Loofah up to 2.25.1 HTML5 Sanitizer cross-domain policy

SecurityVulns

A vulnerability has been found in Flavorjones Loofah up to 2.25.1 and classified as problematic. This affects an unknown function of the component HTML5 Sanitizer. This manipulation causes permissive cross-domain policy with untrusted domains.

This vulnerability is tracked as CVE-2026-73490. The attack is possible to be carried out remotely. No exploit exists.

The affected component should be upgraded.VulDB Recent EntriesRead More