FlawAtlas
Search the atlas
CVE-2018-8048 Moderate

CVE-2018-8048

In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment.

Exploit probability 2.0%
Published March 27, 2018
Required by Not available
Last source change July 8, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

27 explicit affected versions

RubyGems loofah

27 explicit affected versions

RubyGems nokogiri

102 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2018-8048

In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment.

View original source
Open Source Vulnerabilities GHSA-x7rv-cr6v-4vm4

Loofah allows non-whitelisted attributes to be present in sanitized output when input with specially-crafted HTML fragments. Users are affected if running Loofah < 2.2.1, but only: * when running on MRI or RBX, * in combination with libxml2 >= 2.9.2. JRuby users are not affected.

View original source

05 / REFERENCES

Further evidence