git: 41c838702065 - main - security/vuxml: Document py-mkdocs-material vulnerability

Kai Knoblich <[email protected]>
Newsgroups gmane.os.freebsd.devel.cvs.ports
Message-ID <[email protected]>
The branch main has been updated by kai:

URL: https://cgit.FreeBSD.org/ports/commit/?id=41c8387020656062843716983fcd4f5b3c821033

commit 41c8387020656062843716983fcd4f5b3c821033
Author:     Kai Knoblich <[email protected]>
AuthorDate: 2026-07-31 14:18:21 +0000
Commit:     Kai Knoblich <[email protected]>
CommitDate: 2026-07-31 14:18:21 +0000

    security/vuxml: Document py-mkdocs-material vulnerability
---
 security/vuxml/vuln/2026.xml | 31 +++++++++++++++++++++++++++++++
 1 file changed, 31 insertions(+)

diff --git a/security/vuxml/vuln/2026.xml b/security/vuxml/vuln/2026.xml
index 6dbee0632dab..9f363464a26d 100644
--- a/security/vuxml/vuln/2026.xml
+++ b/security/vuxml/vuln/2026.xml
@@ -1,3 +1,34 @@
+  <vuln vid="1976b049-8ccc-11f1-b333-901b0edee044">
+    <topic>py-mkdocs-material -- DOM XSS vulnerability</topic>
+    <affects>
+<package>
+    <name>py311-mkdocs-material</name>
+    <name>py312-mkdocs-material</name>
+    <name>py313-mkdocs-material</name>
+    <name>py313t-mkdocs-material</name>
+    <name>py314-mkdocs-material</name>
+    <name>py314t-mkdocs-material</name>
+    <name>py315-mkdocs-material</name>
+<range><lt>9.7.7</lt></range>
+</package>
+    </affects>
+    <description>
+	<body xmlns="http://www.w3.org/1999/xhtml">
+	<p>Martin Donath reports:</p>
+	<blockquote cite="https://github.com/squidfunk/mkdocs-material/security/advisories/GHSA-xvg9-69gf-fjrf">
+	  <p>Material for MkDocs 7.2.0 through 9.7.6 contains a DOM-based cross-site scripting vulnerability in the optional search.suggest feature. A crafted q URL parameter could execute JavaScript in the documentation site's origin after user interaction.</p>
+	</blockquote>
+	</body>
+    </description>
+    <references>
+      <url>https://github.com/squidfunk/mkdocs-material/security/advisories/GHSA-xvg9-69gf-fjrf</url>
+    </references>
+    <dates>
+      <discovery>2026-07-17</discovery>
+      <entry>2026-07-31</entry>
+    </dates>
+  </vuln>
+
   <vuln vid="0d5b4884-8c2b-11f1-8144-8447094a420f">
     <topic>Weechat -- Multiple vulnerabilities</topic>
     <affects>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.