Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59711

Опубликовано: 06 июл. 2026
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitrary HTML and JavaScript. When completeHTMLDocument option is enabled, unescaped less-than and greater-than characters in markdown frontmatter metadata are inserted directly into HTML title tags, enabling attackers to break out of the title context and execute malicious scripts in the rendered page.

A flaw was found in showdown. This cross-site scripting (XSS) vulnerability occurs in the metadata title handling when the completeHTMLDocument option is enabled. An attacker can exploit this by injecting unescaped less-than and greater-than characters into markdown frontmatter metadata. This allows the attacker to break out of the HTML title context and execute arbitrary HTML and JavaScript, potentially leading to information disclosure or arbitrary code execution in the user's browser.

Отчет

Red Hat rates this flaw as Moderate. Exploitation requires two non-default showdown options enabled simultaneously: metadata and completeHTMLDocument, both of which default to false. Red Hat products that ship showdown do not enable completeHTMLDocument in their default configurations, which reduces the likelihood of exploitation.

Меры по смягчению последствий

Do not enable showdown's completeHTMLDocument option when processing untrusted markdown input. If the option is required, sanitize metadata values before passing them to the converter.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat-openshift-console-plugin-npmFix deferred
Cryostat 4showdownFix deferred
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel9Under investigation
Node HealthCheck Operatorworkload-availability/node-healthcheck-must-gather-rhel9Fix deferred
Node HealthCheck Operatorworkload-availability/node-healthcheck-operator-bundleFix deferred
Node HealthCheck Operatorworkload-availability/node-healthcheck-rhel9-operatorFix deferred
Red Hat 3scale API Management Platform 23scale-amp21/systemFix deferred
Red Hat 3scale API Management Platform 23scale-amp22/systemFix deferred
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel7Fix deferred
Red Hat 3scale API Management Platform 23scale-amp2/system-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2497535showdown: Showdown: Cross-site scripting via unescaped metadata title allows arbitrary code execution

EPSS

Процентиль: 9%
0.00187
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
nvd
28 дней назад

showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitrary HTML and JavaScript. When completeHTMLDocument option is enabled, unescaped less-than and greater-than characters in markdown frontmatter metadata are inserted directly into HTML title tags, enabling attackers to break out of the title context and execute malicious scripts in the rendered page.

CVSS3: 6.1
github
28 дней назад

showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitrary HTML and JavaScript. When completeHTMLDocument option is enabled, unescaped less-than and greater-than characters in markdown frontmatter metadata are inserted directly into HTML title tags, enabling attackers to break out of the title context and execute malicious scripts in the rendered page.

EPSS

Процентиль: 9%
0.00187
Низкий

6.1 Medium

CVSS3