DOM-based XSS in Material for MkDocs by Squidfunk
CVE-2026-73295

5.4MEDIUM

Key Information:

Vendor

Squidfunk

Vendor
CVE Published:
12 August 2026

What is CVE-2026-73295?

The Material for MkDocs documentation framework includes a DOM-based cross-site scripting vulnerability in the optional search.suggest feature. This flaw, present from versions 7.2.0 through 9.7.7, allows an attacker to craft a malicious q URL parameter, which could execute arbitrary JavaScript within the documentation site's origin after user interaction. This vulnerability highlights the need for developers and users to ensure they are operating on the latest version, as it has been addressed in version 9.7.7.

Affected Version(s)

mkdocs-material >= 7.2.0, < 9.7.7

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.