{"id":"CVE-2026-61824","aliases":["GHSA-jg4p-g6xj-4qmf"],"title":"Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors","summary":"Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors","severity":"high","cvss":8.2,"cwe":["CWE-79","CWE-116"],"vendor":"defuddle","product":"defuddle","ecosystem":"npm","affected":["defuddle <= 0.19.0"],"patched":["defuddle 0.19.1"],"published":"2026-08-21","updated":"2026-08-21","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-jg4p-g6xj-4qmf","references":[{"url":"https://github.com/kepano/defuddle/security/advisories/GHSA-jg4p-g6xj-4qmf"},{"url":"https://github.com/kepano/defuddle/pull/326"},{"url":"https://github.com/kepano/defuddle/commit/baf2eaef61d334ef595b28c89e5c5e89e52daf7f"},{"url":"https://github.com/kepano/defuddle/releases/tag/0.19.1"},{"url":"https://github.com/advisories/GHSA-jg4p-g6xj-4qmf"}],"tags":["ghsa","npm"],"ingestedAt":"2026-08-21T21:22:19.700Z","epss":0.00228,"epssPercentile":0.13882,"slug":"CVE-2026-61824","body":"## Overview\n\n## Summary\n\nAn Improper Neutralization of Input During Web Page Generation issue in the site extractor component allows an attacker-controlled attribute value to be injected into output HTML without escaping. An attacker who crafts a malicious HTML page or controls content on a matching domain can execute arbitrary scripts when a victim processes the page, resulting in Cross-Site Scripting (XSS).  This affects defuddle through 0.19.0 and has been patched in version 0.19.1.\n\n## Impact\n\nThis vulnerability allows for Cross-Site Scripting (XSS) execution without needing to compromise external websites. Affected consumers include:\n- Obsidian Web Clipper, \n- web services serving the parsed output directly as HTML, and \n- any downstream application rendering the unsanitized HTML results\n\n## Patch\nThis issue has been patched in defuddle version 0.19.1. Users are encouraged to update to the latest release.\n\n## Affected packages\n\n- `defuddle <= 0.19.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `defuddle 0.19.1`","depth":"twilight","depthScore":45,"depthScoreParts":{"impact":45.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}