highCVSS 8.2Vulnerability

CVE-2026-61824

## Summary An Improper Neutralization of Input During Web Page Generation issue in the site extractor component allows an attacker-controlled attribute value to be injected into output HTML without escaping. An attacker who crafts a malicious HTML page or controls content on a matching domain can execute arbitrary scripts when a victim processes the page, resulting in Cross-Site Scripting (XSS). This affects defuddle through 0.19.0 and has been patched in version 0.19.1. ## Impact This vulnerability allows for Cross-Site Scripting (XSS) execution without needing to compromise external websites. Affected consumers include: - Obsidian Web Clipper, - web services serving the parsed output directly as HTML, and - any downstream application rendering the unsanitized HTML results ## Patch This issue has been patched in defuddle version 0.19.1. Users are encouraged to update to the latest release.

Properties

ghsa_id
GHSA-jg4p-g6xj-4qmf
severity
high
summary
Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors
cvss_score
8.2
cve_id
CVE-2026-61824
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
is_ghsa_only
false
ghsa_published
2026-08-21T20:54:56Z
source_url
https://github.com/advisories/GHSA-jg4p-g6xj-4qmf
ghsa_updated
2026-08-21T20:54:57Z

Related Entities (5)

VULNERABLE_TO (1)

[Software]npm/defuddle

AFFECTS (1)

[Software]npm/defuddle

HAS_WEAKNESS (2)

[Weakness]Improper Encoding or Escaping of Output
[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-61824 (CVSS 8.2) — Ninja Signal Threat Intelligence | Ninja Signal