4 Total advisories
4 Vulnerabilities
0 Malware
Dependency scanning
Check whether showdown is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 6.1
CVE-2026-59711
showdown metadata title handling allows cross-site scripting
MEDIUM 6.1
CVE-2026-59710
showdown allows stored cross-site scripting through table header ID injection
MEDIUM 5.3
CVE-2024-1899
Showdown vulnerable to Regular Expression Denial of Service (ReDoS) in link/anchor parsing
LOW 3.1
GHSA-h6mq-3cj6-h738
Reverse Tabnabbing in showdown
Browse more npm advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes