defuddle is vulnerable to Cross-Site Scripting (XSS)
61
Medium Risk
Defuddle extracts article content and when DOM extraction has insufficient content, falls back to the schema.org JSON-LD articleBody field. This fallback path assigns the externally supplied HTML directly to the extraction result without routing it through the library's sanitizer. A parsed page can place malicious markup in the JSON-LD articleBody, and applications that render the extracted content as HTML then execute the injected script. The fix sanitizes the schema.org fallback HTML before it is returned.
You are affected if you are using a version that falls within the vulnerable range and your application renders Defuddle's extracted content as HTML.
defuddle is vulnerable to Cross-Site Scripting (XSS) in versions 0.9.0 - 0.19.2.
Upgrade the defuddle library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant