{"id":"CVE-2026-61824","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-61824","summary":"Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors","details":"## Summary\n\nAn Improper Neutralization of Input During Web Page Generation issue in the site extractor component allows an attacker-controlled attribute value to be injected into output HTML without escaping. An attacker who crafts a malicious HTML page or controls content on a matching domain can execute arbitrary scripts when a victim processes the page, resulting in Cross-Site Scripting (XSS).  This affects defuddle through 0.19.0 and has been patched in version 0.19.1.\n\n## Impact\n\nThis vulnerability allows for Cross-Site Scripting (XSS) execution without needing to compromise external websites. Affected consumers include:\n- Obsidian Web Clipper, \n- web services serving the parsed output directly as HTML, and \n- any downstream application rendering the unsanitized HTML results\n\n## Patch\nThis issue has been patched in defuddle version 0.19.1. Users are encouraged to update to the latest release.","published":"2026-08-21T20:54:56Z","modified":"2026-08-21T21:00:09.360049238Z","cvss":{"score":8.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"defuddle","fixedVersion":"0.19.1"}],"fix":{"url":"https://github.com/kepano/defuddle/pull/326","label":"kepano/defuddle#326"},"references":[{"type":"WEB","url":"https://github.com/kepano/defuddle/security/advisories/GHSA-jg4p-g6xj-4qmf"},{"type":"WEB","url":"https://github.com/kepano/defuddle/pull/326"},{"type":"WEB","url":"https://github.com/kepano/defuddle/commit/baf2eaef61d334ef595b28c89e5c5e89e52daf7f"},{"type":"PACKAGE","url":"https://github.com/kepano/defuddle"},{"type":"WEB","url":"https://github.com/kepano/defuddle/releases/tag/0.19.1"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-21T21:00:09.360049238Z"}}