DOM-based XSS in Material for MkDocs by Squidfunk
CVE-2026-73295
5.4MEDIUM
What is CVE-2026-73295?
The Material for MkDocs documentation framework includes a DOM-based cross-site scripting vulnerability in the optional search.suggest feature. This flaw, present from versions 7.2.0 through 9.7.7, allows an attacker to craft a malicious q URL parameter, which could execute arbitrary JavaScript within the documentation site's origin after user interaction. This vulnerability highlights the need for developers and users to ensure they are operating on the latest version, as it has been addressed in version 9.7.7.
Affected Version(s)
mkdocs-material >= 7.2.0, < 9.7.7
