Medium severity6.1OSV Advisory· Published Jul 6, 2026· Updated Jul 7, 2026
CVE-2026-59711
CVE-2026-59711
Description
showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitrary HTML and JavaScript. When completeHTMLDocument option is enabled, unescaped less-than and greater-than characters in markdown frontmatter metadata are inserted directly into HTML title tags, enabling attackers to break out of the title context and execute malicious scripts in the rendered page.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
showdownnpm | <= 2.1.0 | — |
Affected products
52.1.0, 2.0.4, 2.0.3, …+ 1 more
- (no CPE)range: 2.1.0, 2.0.4, 2.0.3, …
- (no CPE)
- osv-coords3 versionspkg:apk/chainguard/opensearch-dashboards-3-dashboards-reportingpkg:apk/chainguard/opensearch-dashboards-3-fips-dashboards-reportingpkg:apk/wolfi/opensearch-dashboards-3-dashboards-reporting
< 3.8.0-r0+ 2 more
- (no CPE)range: < 3.8.0-r0
- (no CPE)range: < 3.8.0-r0
- (no CPE)range: < 3.8.0-r0
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-cr32-g25g-vxjjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-59711ghsaADVISORY
- github.com/showdownjs/showdown/commit/184a3e4e97f90e075c4512f2c4c06dcf655e91b7ghsaWEB
- github.com/showdownjs/showdown/issues/1047nvdWEB
- www.vulncheck.com/advisories/showdown-cross-site-scripting-via-unescaped-metadata-title-in-completehtmldocumentnvdWEB
News mentions
0No linked articles in our index yet.