THREAT OPS › Threat News › [GHSA] GHSA-jg4p-g6xj-4qmf (high) — Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors
[GHSA] GHSA-jg4p-g6xj-4qmf (high) — Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors
GHSA-jg4p-g6xj-4qmf Severity: high CVE: CVE-2026-61824
Defuddle vulnerable to XSS via unescaped attribute interpolation in site extractors
## Summary
An Improper Neutralization of Input During Web Page Generation issue in the site extractor component allows an attacker-controlled attribute value to be injected into output HTML without escaping. An attacker who crafts a malicious HTML page or co
MITRE ATT&CK techniques
Indicators of compromise
- CVE-2026-61824cve
Original source: https://github.com/advisories/GHSA-jg4p-g6xj-4qmf