HTML Sanitization Flaw in Defuddle Affects Website Integrity
CVE-2026-61824

8.2HIGH

Key Information:

Vendor

Kepano

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-61824?

The Defuddle product prior to version 0.19.1 is susceptible to an improper input validation vulnerability. This flaw arises from the way HTML content is processed, specifically that site extractors embed page-derived image alt and src values, Open Graph image values, and video descriptions into HTML without proper context-based escaping. Consequently, malicious actors can exploit this weakness by injecting event-handler attributes or JavaScript URLs into the HTML extracted from compromised or attacker-controlled web pages. These unauthorized scripts can execute once a victim or downstream application renders the resulting HTML, potentially leading to significant security breaches.

Affected Version(s)

defuddle < 0.19.1

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.