HIGH
kepano
CVE published 2026-08-21
CVE-2026-61824
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-21T21:17:01.017Z and has not been modified since then. Defuddle prior to version 0.19.1 is vulnerable to HTML injection attacks due to improper escaping of user-derived content. An attacker can inject event-handler attributes or JavaScript URLs that execute when a victim or downstream application re [truncated]