HTML Sanitization Flaw in Defuddle Affects Website Integrity
CVE-2026-61824
8.2HIGH
What is CVE-2026-61824?
The Defuddle product prior to version 0.19.1 is susceptible to an improper input validation vulnerability. This flaw arises from the way HTML content is processed, specifically that site extractors embed page-derived image alt and src values, Open Graph image values, and video descriptions into HTML without proper context-based escaping. Consequently, malicious actors can exploit this weakness by injecting event-handler attributes or JavaScript URLs into the HTML extracted from compromised or attacker-controlled web pages. These unauthorized scripts can execute once a victim or downstream application renders the resulting HTML, potentially leading to significant security breaches.
Affected Version(s)
defuddle < 0.19.1
