CVE-2026-73295

Source
https://cve.org/CVERecord?id=CVE-2026-73295
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73295.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-73295
Aliases
  • GHSA-xvg9-69gf-fjrf
Downstream
Published
2026-08-12T16:15:22.470Z
Modified
2026-08-15T11:31:03.095075038Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Material for MkDocs: DOM XSS in search suggestions via query parameter
Details

Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/templates/assets/javascripts/components/search/suggest/index.ts contains a DOM-based cross-site scripting vulnerability in the optional search.suggest feature that allows a crafted q URL parameter to execute JavaScript in a documentation site's origin after user interaction. This issue is fixed in version 9.7.7.

Database specific
{
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73295.json",
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Git / github.com/squidfunk/mkdocs-material

Affected ranges

Type
GIT
Repo
https://github.com/squidfunk/mkdocs-material
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "7.2.0"
        },
        {
            "fixed": "9.7.7"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

7.*
7.2.0
7.2.1
7.2.2
7.2.3
7.2.4
7.2.5
7.2.6
7.2.7
7.2.8
7.3.0
7.3.1
7.3.2
7.3.3
7.3.4
7.3.5
7.3.6
8.*
8.0.0
8.0.1
8.0.2
8.0.3
8.0.4
8.0.5
8.1.0
8.1.1
8.1.10
8.1.11
8.1.2
8.1.3
8.1.4
8.1.5
8.1.6
8.1.7
8.1.8
8.1.9
8.2.0
8.2.1
8.2.10
8.2.11
8.2.12
8.2.13
8.2.14
8.2.15
8.2.16
8.2.2
8.2.3
8.2.4
8.2.5
8.2.6
8.2.7
8.2.8
8.2.9
8.3.0
8.3.1
8.3.2
8.3.3
8.3.4
8.3.5
8.3.6
8.3.7
8.3.8
8.3.9
8.4.0
8.4.0rc1
8.4.1
8.4.2
8.4.3
8.4.4
8.5.0
8.5.1
8.5.10
8.5.11
8.5.2
8.5.3
8.5.4
8.5.5
8.5.6
8.5.7
8.5.8
8.5.9
9.*
9.0.0
9.0.1
9.0.10
9.0.11
9.0.12
9.0.13
9.0.14
9.0.2
9.0.3
9.0.4
9.0.5
9.0.6
9.0.7
9.0.8
9.0.9
9.1.0
9.1.1
9.1.10
9.1.11
9.1.12
9.1.13
9.1.14
9.1.15
9.1.16
9.1.17
9.1.18
9.1.19
9.1.2
9.1.20
9.1.21
9.1.3
9.1.4
9.1.5
9.1.6
9.1.7
9.1.8
9.1.9
9.2.0
9.2.1
9.2.2
9.2.3
9.2.4
9.2.5
9.2.6
9.2.7
9.2.8
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.10
9.4.11
9.4.12
9.4.13
9.4.14
9.4.2
9.4.3
9.4.4
9.4.5
9.4.6
9.4.7
9.4.8
9.4.9
9.5.0
9.5.1
9.5.10
9.5.11
9.5.12
9.5.13
9.5.14
9.5.15
9.5.16
9.5.17
9.5.18
9.5.19
9.5.2
9.5.20
9.5.21
9.5.22
9.5.23
9.5.24
9.5.25
9.5.26
9.5.27
9.5.28
9.5.29
9.5.3
9.5.30
9.5.31
9.5.32
9.5.33
9.5.34
9.5.35
9.5.36
9.5.37
9.5.38
9.5.39
9.5.4
9.5.40
9.5.41
9.5.42
9.5.43
9.5.44
9.5.45
9.5.46
9.5.47
9.5.48
9.5.49
9.5.5
9.5.50
9.5.6
9.5.7
9.5.8
9.5.9
9.6.0
9.6.1
9.6.10
9.6.11
9.6.12
9.6.13
9.6.14
9.6.15
9.6.16
9.6.17
9.6.18
9.6.19
9.6.2
9.6.20
9.6.21
9.6.22
9.6.23
9.6.3
9.6.4
9.6.5
9.6.6
9.6.7
9.6.8
9.6.9
9.7.0
9.7.1
9.7.2
9.7.3
9.7.4
9.7.5
9.7.6

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73295.json"