Bug 2497535 (CVE-2026-59711) - CVE-2026-59711 showdown: Showdown: Cross-site scripting via unescaped metadata title allows arbitrary code execution
Summary: CVE-2026-59711 showdown: Showdown: Cross-site scripting via unescaped metadat...
Keywords:
Status: NEW
Alias: CVE-2026-59711
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2531306
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-06 22:01 UTC by OSIDB Bzimport
Modified: 2026-09-10 07:46 UTC (History)
45 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-06 22:01:56 UTC
showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitrary HTML and JavaScript. When completeHTMLDocument option is enabled, unescaped less-than and greater-than characters in markdown frontmatter metadata are inserted directly into HTML title tags, enabling attackers to break out of the title context and execute malicious scripts in the rendered page.


Note You need to log in before you can comment on or make changes to this bug.