CVE-2026-73491 | flavorjones Loofah up to 2.25.1 HTML5 Scrub Scrub.allowed_uri? HTML injection

SecurityVulns

A vulnerability classified as problematic has been found in flavorjones Loofah up to 2.25.1. This issue affects the function Loofah::HTML5::Scrub.allowed_uri? of the component HTML5 Scrub. Performing a manipulation results in HTML injection.

This vulnerability was named CVE-2026-73491. The attack may be initiated remotely. There is no available exploit.

It is recommended to upgrade the affected component.VulDB Recent EntriesRead More