A High severity vulnerability affecting defuddle versions <= 0.19.0, CVE-2026-61824 with a CVSS score of 8.2, is an Improper Neutralization of Input During Web Page Generation issue in the site extractor component that allows an attacker-controlled attribute value to be injected into output HTML without escaping, resulting in Cross-Site Scripting (XSS) via unescaped attribute interpolation.
We recommend you to update defuddle to version 0.19.1.[/subscribe_to_unlock_form]
A High severity vulnerability affecting defuddle versions <= 0.19.0, CVE-2026-61824 with a CVSS score of 8.2, is an Improper Neutralization of Input During Web Page Generation issue in the site extractor component that allows an attacker-controlled attribute value to be injected into output HTML without escaping, resulting in Cross-Site Scripting (XSS) via unescaped attribute interpolation.
We recommend you to update defuddle to version 0.19.1.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]