medium · CVSS v3 6.1 · CVSS v4 5.3
CVE-2026-104477
Showdown 2.1.0 contains a cross‑site scripting flaw in its link and image subparsers that fails to escape double quotes in URLs, allowing at
Overview
Showdown 2.1.0 contains a cross‑site scripting flaw in its link and image subparsers that fails to escape double quotes in URLs, allowing attackers to inject JavaScript via crafted markdown. This vulnerability can be triggered when a user views rendered markdown containing malicious links or images. It is a medium‑severity issue that can compromise web applications using Showdown.
Description
Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in destination URLs placed into href and src attributes. Attackers can craft markdown links or images containing a double quote followed by onerror or onmouseover handlers to execute script when victims view rendered HTML.
Impact
The flaw enables attackers to execute arbitrary JavaScript in the victim’s browser, potentially exposing sensitive data, modifying page content, or redirecting users. Users of web applications that render untrusted markdown are at risk, as are administrators who rely on Showdown for content processing.
Remediation
Upgrade Showdown to the latest released version that includes the XSS fix. If an upgrade is not immediately possible, sanitize all URLs before passing them to Showdown, escape double quotes, or disable the link and image parsers. Additionally, enforce a strong Content‑Security‑Policy that blocks inline scripts and restricts script sources.
Risk context
With a CVSS v3 score of 6.1 and no EPSS data, the risk is moderate; defenders should prioritize patching or mitigation in environments that process user‑generated markdown.
Affected products
- Showdown 2.1.0
Scores
- Severity
- medium
- CVSS v2
- 6.4
- CVSS v3
- 6.1
- CVSS v4
- 5.3
- EPSS
- —