Loofah >= 2.1.0, < 2.19.1
is vulnerable to cross-site scripting via the image/svg+xml
media type in data URIs.
Upgrade to Loofah >= 2.19.1
.
The Loofah maintainers have evaluated this as Medium Severity 6.1.
This vulnerability was responsibly reported by Maciej Piechota (@haqpl).