Vulnerability CVE-2022-23515


Published: 2022-12-14

Description:
Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah >= 2.1.0, < 2.19.1 is vulnerable to cross-site scripting via the image/svg+xml media type in data URIs. This issue is patched in version 2.19.1.

Type:

CWE-79

(Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'))

 References:
https://hackerone.com/reports/1694173
https://github.com/flavorjones/loofah/security/advisories/GHSA-228g-948r-83gx
https://github.com/flavorjones/loofah/issues/101

Copyright 2026, cxsecurity.com

 

Back to Top