THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-jg4p-g6xj-4qmf (high) — Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors

[GHSA] GHSA-jg4p-g6xj-4qmf (high) — Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors

medgithub_advisoriesPublished 2026-08-21

GHSA-jg4p-g6xj-4qmf Severity: high CVE: CVE-2026-61824

Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors

## Summary

An Improper Neutralization of Input During Web Page Generation issue in the site extractor component allows an attacker-controlled attribute value to be injected into output HTML without escaping. An attacker who crafts a malicious HTML page or co

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-jg4p-g6xj-4qmf