Impact
The vulnerability is a cross‑site scripting flaw in the showdown library’s markdown to HTML conversion process. The link and image subparsers do not escape double quotes contained in destination URLs, allowing an attacker to inject JavaScript by appending an event handler such as onerror or onmouseover after the quote. When a victim views the rendered HTML, the script runs in the victim’s browser, enabling credential theft, session hijacking, or drive‑by malware installation.
Affected Systems
Any deployment that incorporates showdownjs:showdown version 2.1.0 or earlier and renders user‑supplied markdown without additional sanitization is impacted. This includes web applications, content management systems, or any front‑end libraries that import this version as a dependency.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. Exploitability is reasonably high because the flaw is triggered by crafted input; no special privilege or system access is required. The EPSS score is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Attackers can deliver the malicious markdown through any channel that allows user input to reach the rendering engine. Given the widespread use of showdown in web projects, the potential for exploitation is significant if no mitigations are applied.
OpenCVE Enrichment