Skip to content

[Aikido] Fix 5 security issues in loofah, rails-html-sanitizer - #335

Closed
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/AIK-17308-update-packages-69874631-pe5x
Closed

[Aikido] Fix 5 security issues in loofah, rails-html-sanitizer#335
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/AIK-17308-update-packages-69874631-pe5x

Conversation

@aikido-autofix

Copy link
Copy Markdown

Upgrade loofah and rails-html-sanitizer to fix XSS vulnerabilities in SVG sanitization via unfiltered href attributes and malformed javascript: URI schemes.

✅ 5 CVEs resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
GHSA-9wjq-cp2p-hrgf
LOW
[loofah] Loofah's HTML5 sanitizer failed to restrict the href attribute on SVG elements, allowing external document references that could execute scripts or enable tracking through SVG and elements.
AIKIDO-2026-622262
LOW
[loofah] HTML5 sanitizer fails to restrict the href attribute on SVG elements, allowing Cross-site Scripting (XSS) attacks through external document references in elements like <use> and <feImage>. This enables arbitrary script execution or external content loading when sanitizing user-supplied SVG.
AIKIDO-2026-349881
LOW
[loofah] A Cross-site Scripting (XSS) vulnerability exists due to improper validation of URIs with numeric character references lacking trailing semicolons, allowing malicious scripts like javascript&#58alert(1) to bypass filtering and execute in browsers.
AIKIDO-2026-498891
LOW
[loofah] A vulnerability in the allowed_uri? helper fails to reject javascript: URIs when the scheme is split by HTML5 named character references like &Tab; or &NewLine;, allowing attackers to bypass URI validation and execute arbitrary JavaScript. This affects callers of the public helper method and higher-level features like Action Text markdown link validation that render approved URIs into HTML attributes.
AIKIDO-2026-663658
LOW
[rails-html-sanitizer] A Cross-site Scripting (XSS) vulnerability exists due to incomplete attribute restrictions on SVG elements, allowing href attributes to reference external documents and potentially execute scripts or load external content for tracking purposes.
🔗 Related Tasks

@codecov

codecov Bot commented Jul 19, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@aikido-autofix

Copy link
Copy Markdown
Author

Closed by Aikido: a new AutoFix has been created → #339

@aikido-autofix aikido-autofix Bot closed this Jul 22, 2026
@aikido-autofix
aikido-autofix Bot deleted the fix/AIK-17308-update-packages-69874631-pe5x branch July 22, 2026 23:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants