defuddle
npm2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting defuddlepage 1 of 1
- CVE-2026-30830MEDIUMCVSS 6.1EG 6.1✓ Fixed in 0.9.02026-03-06
Defuddle cleans up HTML pages. Prior to version 0.9.0, the _findContentBySchemaText method in src/defuddle.ts interpolates image src and alt attributes directly into an HTML string without escaping. An attacker can use a " in the alt attri…
- CVE-2026-61824HIGHCVSS 8.2EG 8.2✓ Fixed in 0.19.12026-08-21
Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interpolate page-derived image alt and src values, og:image values, and video descriptions into HTML strings without context-appropriate escaping, and buildExtractorResponse()…
Check whether defuddle is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for defuddle CVEs against the assets you own.
Start Free Scan →