GHSA-22g5-r2x5-97cx

Suggest an improvement
Source
https://github.com/advisories/GHSA-22g5-r2x5-97cx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-22g5-r2x5-97cx/GHSA-22g5-r2x5-97cx.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-22g5-r2x5-97cx
Aliases
Downstream
CGA (12)
MINI (6)
Published
2026-07-07T00:30:59Z
Modified
2026-08-07T21:26:12Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
showdown allows stored cross-site scripting through table header ID injection
Details

showdown contains a stored cross-site scripting vulnerability in the parseHeaders function of src/subParsers/makehtml/tables.js that fails to properly escape table header ID attributes. Attackers can inject arbitrary HTML and script-executing SVG elements through double-quote characters in markdown table headers, achieving stored XSS when untrusted markdown is rendered with the default github flavor configuration.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-08-07T21:03:43Z",
    "nvd_published_at":  "2026-07-06T22:16:50Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / showdown

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.1.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-22g5-r2x5-97cx/GHSA-22g5-r2x5-97cx.json"