CVE-2026-61824
## Summary An Improper Neutralization of Input During Web Page Generation issue in the site extractor component allows an attacker-controlled attribute value to be injected into output HTML without escaping. An attacker who crafts a malicious HTML page or controls content on a matching domain can execute arbitrary scripts when a victim processes the page, resulting in Cross-Site Scripting (XSS). This affects defuddle through 0.19.0 and has been patched in version 0.19.1. ## Impact This vulnerability allows for Cross-Site Scripting (XSS) execution without needing to compromise external websites. Affected consumers include: - Obsidian Web Clipper, - web services serving the parsed output directly as HTML, and - any downstream application rendering the unsanitized HTML results ## Patch This issue has been patched in defuddle version 0.19.1. Users are encouraged to update to the latest release.
Properties
- ghsa_id
- GHSA-jg4p-g6xj-4qmf
- severity
- high
- summary
- Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors
- cvss_score
- 8.2
- cve_id
- CVE-2026-61824
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
- is_ghsa_only
- false
- ghsa_published
- 2026-08-21T20:54:56Z
- source_url
- https://github.com/advisories/GHSA-jg4p-g6xj-4qmf
- ghsa_updated
- 2026-08-21T20:54:57Z
Related Entities (5)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (2)
REPORTED_BY (1)
Explore deeper with Ninja Signal's threat intelligence graph