A AegiFlow
MEDIUMCVSS 5.3EPSS 0.2%

CVE-2026-59711

showdown metadata title handling allows cross-site scripting

Published
2026-07-06
Modified
2026-08-07
EPSS percentile
9%
Aliases
GHSA-cr32-g25g-vxjj
Sources
github-advisory

Summary

showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitrary HTML and JavaScript. When completeHTMLDocument option is enabled, unescaped less-than and greater-than characters in markdown frontmatter metadata are inserted directly into HTML title tags, enabling attackers to break out of the title context and execute malicious scripts in the rendered page.

Affected packages

EcosystemPackageAffected versionsFixed versions
npmshowdown

Remediation: No patched version is listed by GitHub.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.