---
id: CVE-2026-104477
title: >-
  Showdown through 2.1.0 contains a cross-site scripting vulnerability in the
  makehtml link and image subparsers, which fail to escape double quotes in
  destination URLs placed into href and src attributes
summary: >-
  Showdown through 2.1.0 contains a cross-site scripting vulnerability in the
  makehtml link and image subparsers, which fail to escape double quotes in
  destination URLs placed into href and src attributes. Attackers can craft
  markdown link…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: showdownjs
product: showdown
affected:
  - showdown <= 2.1.0
published: '2026-10-03'
updated: '2026-10-03'
sourceUpdated: '2026-10-03T00:16:35.920'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104477'
references:
  - url: 'https://github.com/showdownjs/showdown'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/showdownjs/showdown/commit/4fb992cd26631c108ec0410342630c80207ec7c6
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/showdown-through-2.1.0-xss-via-unescaped-quote-in-href-and-src-attributes
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-02T23:34:57.409Z'
---

## Overview

Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in destination URLs placed into href and src attributes. Attackers can craft markdown links or images containing a double quote followed by onerror or onmouseover handlers to execute script when victims view rendered HTML.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
