{"id":"GHSA-jg4p-g6xj-4qmf","summary":"Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors","details":"## Summary\n\nAn Improper Neutralization of Input During Web Page Generation issue in the site extractor component allows an attacker-controlled attribute value to be injected into output HTML without escaping. An attacker who crafts a malicious HTML page or controls content on a matching domain can execute arbitrary scripts when a victim processes the page, resulting in Cross-Site Scripting (XSS).  This affects defuddle through 0.19.0 and has been patched in version 0.19.1.\n\n## Impact\n\nThis vulnerability allows for Cross-Site Scripting (XSS) execution without needing to compromise external websites. Affected consumers include:\n- Obsidian Web Clipper, \n- web services serving the parsed output directly as HTML, and \n- any downstream application rendering the unsanitized HTML results\n\n## Patch\nThis issue has been patched in defuddle version 0.19.1. Users are encouraged to update to the latest release.","aliases":["CVE-2026-61824"],"modified":"2026-08-21T21:10:59.866904Z","published":"2026-08-21T20:54:56Z","database_specific":{"github_reviewed_at":"2026-08-21T20:54:56Z","nvd_published_at":null,"cwe_ids":["CWE-116","CWE-79"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/kepano/defuddle/security/advisories/GHSA-jg4p-g6xj-4qmf"},{"type":"WEB","url":"https://github.com/kepano/defuddle/pull/326"},{"type":"WEB","url":"https://github.com/kepano/defuddle/commit/baf2eaef61d334ef595b28c89e5c5e89e52daf7f"},{"type":"PACKAGE","url":"https://github.com/kepano/defuddle"},{"type":"WEB","url":"https://github.com/kepano/defuddle/releases/tag/0.19.1"}],"affected":[{"package":{"name":"defuddle","ecosystem":"npm","purl":"pkg:npm/defuddle"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.19.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.19.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/08/GHSA-jg4p-g6xj-4qmf/GHSA-jg4p-g6xj-4qmf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N"}]}