git: 41c838702065 - main - security/vuxml: Document py-mkdocs-material vulnerability
Kai Knoblich <[email protected]>
| Newsgroups | gmane.os.freebsd.devel.cvs.ports |
|---|---|
| Message-ID | <[email protected]> |
The branch main has been updated by kai: URL: https://cgit.FreeBSD.org/ports/commit/?id=41c8387020656062843716983fcd4f5b3c821033 commit 41c8387020656062843716983fcd4f5b3c821033 Author: Kai Knoblich <[email protected]> AuthorDate: 2026-07-31 14:18:21 +0000 Commit: Kai Knoblich <[email protected]> CommitDate: 2026-07-31 14:18:21 +0000 security/vuxml: Document py-mkdocs-material vulnerability --- security/vuxml/vuln/2026.xml | 31 +++++++++++++++++++++++++++++++ 1 file changed, 31 insertions(+) diff --git a/security/vuxml/vuln/2026.xml b/security/vuxml/vuln/2026.xml index 6dbee0632dab..9f363464a26d 100644 --- a/security/vuxml/vuln/2026.xml +++ b/security/vuxml/vuln/2026.xml @@ -1,3 +1,34 @@ + <vuln vid="1976b049-8ccc-11f1-b333-901b0edee044"> + <topic>py-mkdocs-material -- DOM XSS vulnerability</topic> + <affects> +<package> + <name>py311-mkdocs-material</name> + <name>py312-mkdocs-material</name> + <name>py313-mkdocs-material</name> + <name>py313t-mkdocs-material</name> + <name>py314-mkdocs-material</name> + <name>py314t-mkdocs-material</name> + <name>py315-mkdocs-material</name> +<range><lt>9.7.7</lt></range> +</package> + </affects> + <description> + <body xmlns="http://www.w3.org/1999/xhtml"> + <p>Martin Donath reports:</p> + <blockquote cite="https://github.com/squidfunk/mkdocs-material/security/advisories/GHSA-xvg9-69gf-fjrf"> + <p>Material for MkDocs 7.2.0 through 9.7.6 contains a DOM-based cross-site scripting vulnerability in the optional search.suggest feature. A crafted q URL parameter could execute JavaScript in the documentation site's origin after user interaction.</p> + </blockquote> + </body> + </description> + <references> + <url>https://github.com/squidfunk/mkdocs-material/security/advisories/GHSA-xvg9-69gf-fjrf</url> + </references> + <dates> + <discovery>2026-07-17</discovery> + <entry>2026-07-31</entry> + </dates> + </vuln> + <vuln vid="0d5b4884-8c2b-11f1-8144-8447094a420f"> <topic>Weechat -- Multiple vulnerabilities</topic> <affects>