Vulnerabilities/

Reverse Tabnabbing in showdown

Severity:
Low

Description

Versions of showdown prior to 1.9.1 are vulnerable to Reverse Tabnabbing. The package uses target='_blank' in anchor tags, allowing attackers to access window.opener for the original page when opening links. This is commonly used for phishing attacks.

Recommendation

Update the showdown package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
showdown
Anything's wrong? Let us know Last updated on April 05, 2023

This issue is available in SmartScanner Professional

See Pricing