PYSEC-2026-3864
Dashboard / Vulnerabilities / PYSEC-2026-3864
PYSEC-2026-3864
Summary: Material for MkDocs: DOM XSS in search suggestions via query parameter
Details: ### Impact Material for MkDocs 7.2.0 through 9.7.6 contains a DOM-based cross-site scripting vulnerability in the optional `search.suggest` feature. A crafted `q` URL parameter could execute JavaScript in the documentation site's origin after user interaction. ### Patches The issue is fixed in Material for MkDocs 9.7.7. Users should upgrade to 9.7.7 or later. ### Workarounds Sites unable to upgrade should disable the `search.suggest` feature.
References: https://github.com/squidfunk/mkdocs-material/security/advisories/GHSA-xvg9-69gf-fjrf, https://nvd.nist.gov/vuln/detail/CVE-2026-73295, https://github.com/squidfunk/mkdocs-material/commit/52fb6be8aafe326419f34dc94d3211e7bbfbfb25, https://github.com/squidfunk/mkdocs-material, https://github.com/squidfunk/mkdocs-material/releases/tag/9.7.7, https://pypi.org/project/mkdocs-material, https://github.com/advisories/GHSA-xvg9-69gf-fjrf
Affected packages
Package
Name: mkdocs-material
Purl: pkg:pypi/mkdocs-material
Affected ranges
Type: ECOSYSTEM
Events:
