VDB
Sign up
LOW3.1

GHSA-h6mq-3cj6-h738

Reverse Tabnabbing in showdown

Quick fix

GHSA-h6mq-3cj6-h738 — showdown: upgrade to the fixed version with the command below.

npm install showdown@1.9.1

Details

Versions of `showdown` prior to 1.9.1 are vulnerable to [Reverse Tabnabbing](https://www.owasp.org/index.php/Reverse_Tabnabbing). The package uses `target='_blank'` in anchor tags, allowing attackers to access `window.opener` for the original page when opening links. This is commonly used for phishing attacks.

## Recommendation

Upgrade to version 1.9.1 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/showdown
Introduced in: 0Fixed in: 1.9.1
Fixnpm install showdown@1.9.1

References