GHSA-xvg9-69gf-fjrf

    Dashboard / Vulnerabilities / GHSA-xvg9-69gf-fjrf

    GHSA-xvg9-69gf-fjrf

    Published: 3 Sept 2026Last Modified: 3 Sept 2026

    Summary: Material for MkDocs: DOM XSS in search suggestions via query parameter

    Details: ### Impact Material for MkDocs 7.2.0 through 9.7.6 contains a DOM-based cross-site scripting vulnerability in the optional `search.suggest` feature. A crafted `q` URL parameter could execute JavaScript in the documentation site's origin after user interaction. ### Patches The issue is fixed in Material for MkDocs 9.7.7. Users should upgrade to 9.7.7 or later. ### Workarounds Sites unable to upgrade should disable the `search.suggest` feature.

    Affected packages

    Package

    Name: mkdocs-material

    Purl: pkg:pypi/mkdocs-material

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 7.2.0
    Fixed -9.7.7

    Affected versions

    7.2.0
    7.2.1
    7.2.2
    7.2.3
    7.2.4
    7.2.5
    7.2.6
    7.2.7
    7.2.8

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High