{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/defuddle/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-61824"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Defuddle"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eDefuddle versions through 0.19.0 contain a vulnerability (CVE-2026-61824) related to improper input neutralization in its site extractor component. The library fails to correctly escape attribute values when interpolating them into generated HTML. This flaw allows an attacker who controls the input source or the content of a site being processed by Defuddle to inject malicious scripts into the resulting HTML output.\u003c/p\u003e\n\u003cp\u003eWhen downstream applications, such as the Obsidian Web Clipper or web services that render Defuddle's output directly, display this unsanitized HTML to a user, the malicious script executes in the context of the user's browser. This enables typical XSS-based attacks, including session hijacking, credential theft, or unauthorized actions performed on behalf of the victim. The vulnerability is addressed in version 0.19.1.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in Cross-Site Scripting (XSS) within the context of any application utilizing the Defuddle library to render content. This poses a significant risk to users of tools like the Obsidian Web Clipper and custom web services that rely on the library to parse and display external HTML. The ability to execute arbitrary scripts allows for potential account takeover or sensitive data exposure depending on the privileges of the victim and the scope of the affected application.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate all instances of the Defuddle npm package to version 0.19.1 or later to remediate CVE-2026-61824. Developers integrating Defuddle into web-based services should implement strict Content Security Policy (CSP) headers and ensure that all content rendered from site extraction processes is passed through a sanitization library before being injected into the DOM.\u003c/p\u003e\n","date_modified":"2026-08-22T01:17:43Z","date_published":"2026-08-22T01:17:43Z","id":"https://feed.craftedsignal.io/briefs/2026-08-defuddle-xss/","summary":"The Defuddle library contains an Improper Neutralization of Input vulnerability leading to Cross-Site Scripting (XSS) in applications that render unescaped site extraction output.","title":"Defuddle XSS Vulnerability in Site Extractors","url":"https://feed.craftedsignal.io/briefs/2026-08-defuddle-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Defuddle","version":"https://jsonfeed.org/version/1.1"}