CVE-2026-30830Disclosure(kepano / defuddle)

LOWCVSS 6.1 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Defuddle cleans up HTML pages. Prior to version 0.9.0, the _findContentBySchemaText method in src/defuddle.ts interpolates image src and alt attributes directly into an HTML string without escaping. An attacker can use a " in the alt attribute to break out of the attribute context and inject event handler. This issue has been patched in version 0.9.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • defuddle

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
defuddle

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-03-07: 3Technical Details · 2026-03-07: 303-07
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-30830 Defuddle cleans up HTML pages. Prior to version 0.9.0, the _findContentBySchemaText method in src/defuddle.ts interpolates image src and alt attributes directly into … https://www.cve.org/CVERecord?id=CVE-2026-30830

    Post summary

    The post reports a newly disclosed vulnerability in Defuddle, detailing the problematic code path, but no exploitation evidence, PoC, patch or false‑positive claims are provided.

    00000140
    56.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-30830 - Defuddle: XSS via unescaped string interpolation in _findContentBySchemaText image tag Intel Report: https://ift.tt/uviT40L

    Post summary

    An alert was issued for CVE-2026-30830 describing an XSS flaw in Defuddle via unescaped string interpolation in the _findContentBySchemaText image tag, with no mention of PoC, exploit code, active exploitation, or patch.

    0000041
    344 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-30830 Cross-Site Scripting in Defuddle Before 0.9.0 via Unescaped Image Attributes https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-30830

    Post summary

    A new cross‑site scripting vulnerability (CVE‑2026‑30830) was disclosed for Defuddle versions before 0.9.0, with an unescaped image attribute flaw, but no PoC, exploit, patch, or evidence of active exploitation is provided.

    0000054
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkepanodefuddle-node.js-

Explore more