{"id":"CVE-2026-59710","aliases":["GHSA-22g5-r2x5-97cx"],"url":"https://o3.security/vulnerability/CVE-2026-59710","summary":"showdown - Stored XSS via Unescaped Table Header ID Attribute Injection","details":"showdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/tables.js that fails to properly escape table header ID attributes. Attackers can inject arbitrary HTML and script-executing SVG elements through double-quote characters in markdown table headers, achieving stored XSS when untrusted markdown is rendered with the default github flavor configuration.","published":"2026-07-06T21:15:45.900Z","modified":"2026-08-19T21:41:59.153402897Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"showdown","fixedVersion":null}],"fix":{"url":"https://github.com/showdownjs/showdown/commit/e5cab1e9a5dcea2bb3cbf888863fa7e65ab37edf","label":"showdownjs/showdown@e5cab1e"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59710.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-59710"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/showdown-stored-xss-via-unescaped-table-header-id-attribute-injection"},{"type":"REPORT","url":"https://github.com/showdownjs/showdown/issues/1046"},{"type":"FIX","url":"https://github.com/showdownjs/showdown/commit/e5cab1e9a5dcea2bb3cbf888863fa7e65ab37edf"},{"type":"PACKAGE","url":"https://github.com/showdownjs/showdown"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-19T21:41:59.153402897Z"}}