๐Ÿ” CVE Alert

CVE-2026-104477

MEDIUM 6.1

Showdown through 2.1.0 XSS via unescaped quote in href and src attributes

CVSS Score
6.1
EPSS Score
0.0%
EPSS Percentile
0th

Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in destination URLs placed into href and src attributes. Attackers can craft markdown links or images containing a double quote followed by onerror or onmouseover handlers to execute script when victims view rendered HTML.

CWE CWE-79
Vendor showdownjs
Product showdown
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for showdownjs showdown

Be the first to know when new medium vulnerabilities affecting showdownjs showdown are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

showdownjs / showdown
0 โ‰ค 2.1.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/showdownjs/showdown/commit/4fb992cd26631c108ec0410342630c80207ec7c6 github.com: https://github.com/showdownjs/showdown vulncheck.com: https://www.vulncheck.com/advisories/showdown-through-2.1.0-xss-via-unescaped-quote-in-href-and-src-attributes

Credits

Muhammad Sobirov