rootpwn

medium · CVSS v3 6.1 · CVSS v4 5.3

CVE-2026-104477

Showdown 2.1.0 contains a cross‑site scripting flaw in its link and image subparsers that fails to escape double quotes in URLs, allowing at

Overview

Showdown 2.1.0 contains a cross‑site scripting flaw in its link and image subparsers that fails to escape double quotes in URLs, allowing attackers to inject JavaScript via crafted markdown. This vulnerability can be triggered when a user views rendered markdown containing malicious links or images. It is a medium‑severity issue that can compromise web applications using Showdown.

Description

Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in destination URLs placed into href and src attributes. Attackers can craft markdown links or images containing a double quote followed by onerror or onmouseover handlers to execute script when victims view rendered HTML.

Impact

The flaw enables attackers to execute arbitrary JavaScript in the victim’s browser, potentially exposing sensitive data, modifying page content, or redirecting users. Users of web applications that render untrusted markdown are at risk, as are administrators who rely on Showdown for content processing.

Remediation

Upgrade Showdown to the latest released version that includes the XSS fix. If an upgrade is not immediately possible, sanitize all URLs before passing them to Showdown, escape double quotes, or disable the link and image parsers. Additionally, enforce a strong Content‑Security‑Policy that blocks inline scripts and restricts script sources.

Risk context

With a CVSS v3 score of 6.1 and no EPSS data, the risk is moderate; defenders should prioritize patching or mitigation in environments that process user‑generated markdown.

Affected products

  • Showdown 2.1.0

Scores

Severity
medium
CVSS v2
6.4
CVSS v3
6.1
CVSS v4
5.3
EPSS
—

xss markdown showdown client-side webapp content-sanitization

← All CVEs