Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/templates/assets/javascripts/components/search/suggest/index.ts contains a DOM-based cross-site scripting vulnerability in the optional search.suggest feature that allows a crafted q URL parameter to execute JavaScript in a documentation site's origin after user interaction. This issue is fixed in version 9.7.7.
Metrics
Affected Vendors & Products
References
History
Thu, 13 Aug 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Squidfunk
Squidfunk mkdocs-material |
|
| Vendors & Products |
Squidfunk
Squidfunk mkdocs-material |
Wed, 12 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/templates/assets/javascripts/components/search/suggest/index.ts contains a DOM-based cross-site scripting vulnerability in the optional search.suggest feature that allows a crafted q URL parameter to execute JavaScript in a documentation site's origin after user interaction. This issue is fixed in version 9.7.7. | |
| Title | Material for MkDocs: DOM XSS in search suggestions via query parameter | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-08-12T16:15:22.470Z
Reserved: 2026-08-11T19:42:11.450Z
Link: CVE-2026-73295
No data.
Status : Received
Published: 2026-08-12T17:17:32.637
Modified: 2026-08-12T17:17:32.637
Link: CVE-2026-73295
No data.
OpenCVE Enrichment
Updated: 2026-08-13T09:48:24Z