showdown allows stored cross-site scripting through table header ID injection
- Severity:
- Medium
Description
showdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/tables.js that fails to properly escape table header ID attributes.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.1.0
References
Related Issues
- showdown metadata title handling allows cross-site scripting - CVE-2026-59711
- beautiful-mermaid contains an SVG attribute injection issue that can lead to cross-site scripting (XSS) - CVE-2026-26226
- Open WebUI Has Stored Cross-Site Scripting in SVG Renderer - CVE-2026-45346
- TinyMCE Cross-Site Scripting (XSS) vulnerability using sanitization bypass through nested SVGs - CVE-2026-47760
You might also like:
- Tags:
- npm
- showdown
Anything's wrong? Let us know Last updated on August 07, 2026


