Description
showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitrary HTML and JavaScript.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.1.0
References
Related Issues
- showdown allows stored cross-site scripting through table header ID injection - CVE-2026-59710
- Vulnogram contains a stored cross-site scripting vulnerability in comment hypertext handling - CVE-2026-32774
- DbGate has cross site scripting via the SVG Icon String Handler component - CVE-2026-6216
- CKEditor 5 has Cross-site Scripting (XSS) in the HTML Support package - CVE-2026-28343
You might also like:
- Tags:
- npm
- showdown
Anything's wrong? Let us know Last updated on August 07, 2026


