Junglewise Threat Intelligence

CVE-2026-59710: Showdown stored XSS in table header ID attributes

CVE-2026-59710 · Severity: medium · CVSS 6.1 · Published 2026-07-06

Technologies: showdown (npm). Vendors: npm.

Executive brief

Showdown is a popular JavaScript library that converts Markdown to HTML. A stored cross-site scripting vulnerability in its table parsing function allows attackers to inject malicious code that executes in users' browsers when rendered markdown is displayed. This vulnerability is enabled by default when using showdown's GitHub flavor configuration, putting many applications at risk of account compromise or data theft if they process untrusted markdown.

Technical details

The vulnerability exists in the parseHeaders function of src/subParsers/makehtml/tables.js, which generates HTML id attributes for table headers. The function performs minimal sanitization—only replacing spaces with underscores and lowercasing text—but fails to HTML-escape special characters like double quotes, angle brackets, and ampersands. An attacker can break out of the id attribute using a double quote and inject arbitrary HTML and SVG elements. Since HTML5 parsers treat "/" in tag names as a self-closing tag indicator, payloads like <svg/onload=alert(1)> execute JavaScript without needing spaces. The vulnerability is stored (persists in rendered output) and affects all versions of showdown through 2.1.0. The GitHub flavor configuration enables tablesHeaderId by default, making this the most common attack vector. A patch was committed to the repository on 2026-07-05.

Affected products

  • showdownjs showdown through 2.1.0

Timeline

  • 2026-07-06: disclosed: NVD published
  • 2026-07-07: advisory: GHSA-22g5-r2x5-97cx published
  • 2026-07-05: patched: Fix committed to repository (commit e5cab1e9a5dcea2bb3cbf888863fa7e65ab37edf)

References

Related threats