Medium severity6.1OSV Advisory· Published Jul 6, 2026· Updated Jul 7, 2026
CVE-2026-59710
CVE-2026-59710
Description
showdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/tables.js that fails to properly escape table header ID attributes. Attackers can inject arbitrary HTML and script-executing SVG elements through double-quote characters in markdown table headers, achieving stored XSS when untrusted markdown is rendered with the default github flavor configuration.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
showdownnpm | <= 2.1.0 | — |
Affected products
53.0.0-rc2, 3.0.0-rc1, 1.8.5, …+ 1 more
- (no CPE)range: 3.0.0-rc2, 3.0.0-rc1, 1.8.5, …
- (no CPE)
- osv-coords3 versionspkg:apk/chainguard/opensearch-dashboards-3-dashboards-reportingpkg:apk/chainguard/opensearch-dashboards-3-fips-dashboards-reportingpkg:apk/wolfi/opensearch-dashboards-3-dashboards-reporting
< 3.8.0-r0+ 2 more
- (no CPE)range: < 3.8.0-r0
- (no CPE)range: < 3.8.0-r0
- (no CPE)range: < 3.8.0-r0
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-22g5-r2x5-97cxghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-59710ghsaADVISORY
- github.com/showdownjs/showdown/commit/e5cab1e9a5dcea2bb3cbf888863fa7e65ab37edfnvdWEB
- github.com/showdownjs/showdown/issues/1046nvdWEB
- www.vulncheck.com/advisories/showdown-stored-xss-via-unescaped-table-header-id-attribute-injectionnvdWEB
News mentions
0No linked articles in our index yet.