GHSA-cr32-g25g-vxjjMediumCVSS 6.1

showdown metadata title handling allows cross-site scripting

Published
July 6, 2026
Last Modified
August 7, 2026

🔗 CVE IDs covered (1)

📋 Description

showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitrary HTML and JavaScript. When completeHTMLDocument option is enabled, unescaped less-than and greater-than characters in markdown frontmatter metadata are inserted directly into HTML title tags, enabling attackers to break out of the title context and execute malicious scripts in the rendered page.

🎯 Affected products1

  • npm/showdown:<= 2.1.0

🔗 References (6)