Hi,
The following vulnerability was published for mkdocs-material.
CVE-2026-73295[0]:
| Material for MkDocs is a powerful documentation framework built on
| top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest
| function in
| src/templates/assets/javascripts/components/search/suggest/index.ts
| contains a DOM-based cross-site scripting vulnerability in the
| optional search.suggest feature that allows a crafted q URL
| parameter to execute JavaScript in a documentation site's origin
| after user interaction. This issue is fixed in version 9.7.7.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-73295
https://www.cve.org/CVERecord?id=CVE-2026-73295
[1] https://github.com/squidfunk/mkdocs-material/security/advisories/GHSA-xvg9-69gf-fjrf
[2] https://github.com/squidfunk/mkdocs-material/commit/52fb6be8aafe326419f34dc94d3211e7bbfbfb25
Please adjust the affected versions in the BTS as needed.
Regards,
Salvatore