#1144348 mkdocs-material: CVE-2026-73295

Package:
src:mkdocs-material
Source:
src:mkdocs-material
Submitter:
Salvatore Bonaccorso
Date:
2026-08-14 07:07:02 UTC
Severity:
normal
Tags:
#1144348#5
Date:
2026-08-14 07:05:19 UTC
From:
To:
Hi,

The following vulnerability was published for mkdocs-material.

CVE-2026-73295[0]:
| Material for MkDocs is a powerful documentation framework built on
| top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest
| function in
| src/templates/assets/javascripts/components/search/suggest/index.ts
| contains a DOM-based cross-site scripting vulnerability in the
| optional search.suggest feature that allows a crafted q URL
| parameter to execute JavaScript in a documentation site's origin
| after user interaction. This issue is fixed in version 9.7.7.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-73295
https://www.cve.org/CVERecord?id=CVE-2026-73295
[1] https://github.com/squidfunk/mkdocs-material/security/advisories/GHSA-xvg9-69gf-fjrf
[2] https://github.com/squidfunk/mkdocs-material/commit/52fb6be8aafe326419f34dc94d3211e7bbfbfb25

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore