Feed/CVE-2026-61824
CVE-2026-61824HIGHCVSS 8.2

Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors

Published Aug 21, 2026·Updated Aug 21, 2026

NVD Description

## Summary An Improper Neutralization of Input During Web Page Generation issue in the site extractor component allows an attacker-controlled attribute value to be injected into output HTML without escaping. An attacker who crafts a malicious HTML page or controls content on a matching domain can execute arbitrary scripts when a victim processes the page, resulting in Cross-Site Scripting (XSS). This affects defuddle through 0.19.0 and has been patched in version 0.19.1. ## Impact This vulnerability allows for Cross-Site Scripting (XSS) execution without needing to compromise external websites. Affected consumers include: - Obsidian Web Clipper, - web services serving the parsed output directly as HTML, and - any downstream application rendering the unsanitized HTML results ## Patch This issue has been patched in defuddle version 0.19.1. Users are encouraged to update to the latest release.

Affected Packages (1)

defuddleNPM
Fixed in = 0.19.0

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free