CVE-2026-59710

Source
https://cve.org/CVERecord?id=CVE-2026-59710
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59710.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-59710
Aliases
Published
2026-07-06T21:15:45.900Z
Modified
2026-08-07T21:25:59.283165547Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
showdown - Stored XSS via Unescaped Table Header ID Attribute Injection
Details

showdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/tables.js that fails to properly escape table header ID attributes. Attackers can inject arbitrary HTML and script-executing SVG elements through double-quote characters in markdown table headers, achieving stored XSS when untrusted markdown is rendered with the default github flavor configuration.

Database specific
{
    "cna_assigner": "VulnCheck",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59710.json",
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Git / github.com/showdownjs/showdown

Affected ranges

Type
GIT
Repo
https://github.com/showdownjs/showdown
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "2.1.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

0.*
0.4.0
0.5.0
0.5.1
1.*
1.0.0
1.0.0-alpha.2
1.0.0-alpha1
1.0.1
1.0.2
1.1.0
1.2.0
1.2.1
1.2.2
1.3.0
1.4.0
1.4.2
1.4.3
1.4.4
1.5.0
1.5.1
1.5.2
1.5.3
1.5.4
1.5.5
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.7.0
1.7.1
1.7.2
1.7.3
1.7.4
1.7.5
1.7.6
1.8.0
1.8.1
1.8.2
1.8.3
1.8.4
1.8.5
3.*
3.0.0-rc1
3.0.0-rc2
v0.*
v0.3.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59710.json"