Vulnerabilities/

showdown allows stored cross-site scripting through table header ID injection

Severity:
Medium

Description

showdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/tables.js that fails to properly escape table header ID attributes.

Recommendation

No fix is available yet. Followings are affected versions:

References

Related Issues

Tags:
npm
showdown
Anything's wrong? Let us know Last updated on August 07, 2026