CVE-2026-104477
Showdown through 2.1.0 XSS via unescaped quote in href and src attributes
CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th
Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in destination URLs placed into href and src attributes. Attackers can craft markdown links or images containing a double quote followed by onerror or onmouseover handlers to execute script when victims view rendered HTML.
| CWE | CWE-79 |
| Vendor | showdownjs |
| Product | showdown |
| Published | Oct 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for showdownjs showdown
Be the first to know when new medium vulnerabilities affecting showdownjs showdown are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None
Affected Versions
showdownjs / showdown
0 โค 2.1.0
References
Credits
Muhammad Sobirov