CVE-2026-104477

CVE-2026-104477 published: Showdown through 2.1.0 contains a cross-site scripting vulnerability in the makehtml link and image subparsers, which fail to escape double quotes in destination URLs placed into href and src attributes. Attackers can craft markdown links or images containi...

View full NVD advisory → ← Back to CVE watch