Kepano

Defuddle

2 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.23%
  • Veröffentlicht 21.08.2026 21:17:01
  • Zuletzt bearbeitet 21.08.2026 21:17:01

Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interpolate page-derived image alt and src values, og:image values, and video descriptions into HTML strings without context-appropriate escaping, and buildExtractorResponse() returns th...

Exploit
  • EPSS 0.25%
  • Veröffentlicht 07.03.2026 05:49:15
  • Zuletzt bearbeitet 11.03.2026 18:50:35

Defuddle cleans up HTML pages. Prior to version 0.9.0, the _findContentBySchemaText method in src/defuddle.ts interpolates image src and alt attributes directly into an HTML string without escaping. An attacker can use a " in the alt attribute to bre...