Bug#1144348: mkdocs-material: CVE-2026-73295
Salvatore Bonaccorso <[email protected]>
| Newsgroups | gmane.linux.debian.qa-packages |
|---|---|
| Message-ID | <178669111999.1041942.11827589168059189027.reportbug__31960.1843295217$1786691253$gmane$org@eldamar.lan> |
Source: mkdocs-material Version: 9.6.4-1 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]> Hi, The following vulnerability was published for mkdocs-material. CVE-2026-73295[0]: | Material for MkDocs is a powerful documentation framework built on | top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest | function in | src/templates/assets/javascripts/components/search/suggest/index.ts | contains a DOM-based cross-site scripting vulnerability in the | optional search.suggest feature that allows a crafted q URL | parameter to execute JavaScript in a documentation site's origin | after user interaction. This issue is fixed in version 9.7.7. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-73295 https://www.cve.org/CVERecord?id=CVE-2026-73295 [1] https://github.com/squidfunk/mkdocs-material/security/advisories/GHSA-xvg9-69gf-fjrf [2] https://github.com/squidfunk/mkdocs-material/commit/52fb6be8aafe326419f34dc94d3211e7bbfbfb25 Please adjust the affected versions in the BTS as needed. Regards, Salvatore