Skip to content

chore(deps): Update dependency mkdocs-material to v9.7.7 [SECURITY] - #213

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/pypi-mkdocs-material-vulnerability
Open

chore(deps): Update dependency mkdocs-material to v9.7.7 [SECURITY]#213
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/pypi-mkdocs-material-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
mkdocs-material (changelog) 9.7.69.7.7 age confidence

Material for MkDocs: DOM XSS in search suggestions via query parameter

CVE-2026-73295 / GHSA-xvg9-69gf-fjrf

More information

Details

Impact

Material for MkDocs 7.2.0 through 9.7.6 contains a DOM-based cross-site scripting vulnerability in the optional search.suggest feature. A crafted q URL parameter could execute JavaScript in the documentation site's origin after user interaction.

Patches

The issue is fixed in Material for MkDocs 9.7.7. Users should upgrade to 9.7.7 or later.

Workarounds

Sites unable to upgrade should disable the search.suggest feature.

Severity

  • CVSS Score: 5.4 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


  • If you want to rebase/retry this PR, check this box

@renovate
renovate Bot requested a review from edithatogo as a code owner September 4, 2026 01:39
@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Sep 4, 2026
@github-actions

github-actions Bot commented Sep 4, 2026

Copy link
Copy Markdown
Contributor

🎉 Welcome @renovate[bot]! Thank you for your first pull request to mars! We're excited to have you as a contributor. Our team will review your PR soon. In the meantime, please ensure all CI checks pass.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants