A AegiFlow
MEDIUMCVSS 5.3EPSS 0.2%

CVE-2026-59710

showdown allows stored cross-site scripting through table header ID injection

Published
2026-07-07
Modified
2026-08-07
EPSS percentile
10%
Aliases
GHSA-22g5-r2x5-97cx
Sources
github-advisory

Summary

showdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/tables.js that fails to properly escape table header ID attributes. Attackers can inject arbitrary HTML and script-executing SVG elements through double-quote characters in markdown table headers, achieving stored XSS when untrusted markdown is rendered with the default github flavor configuration.

Affected packages

EcosystemPackageAffected versionsFixed versions
npmshowdown

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.