{"id":"CVE-2026-73295","summary":"Material for MkDocs: DOM XSS in search suggestions via query parameter","details":"Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/templates/assets/javascripts/components/search/suggest/index.ts contains a DOM-based cross-site scripting vulnerability in the optional search.suggest feature that allows a crafted q URL parameter to execute JavaScript in a documentation site's origin after user interaction. This issue is fixed in version 9.7.7.","aliases":["GHSA-xvg9-69gf-fjrf"],"modified":"2026-08-15T11:31:03.095075038Z","published":"2026-08-12T16:15:22.470Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73295.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-79"]},"references":[{"type":"WEB","url":"https://github.com/squidfunk/mkdocs-material/releases/tag/9.7.7"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/73xxx/CVE-2026-73295.json"},{"type":"ADVISORY","url":"https://github.com/squidfunk/mkdocs-material/security/advisories/GHSA-xvg9-69gf-fjrf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-73295"},{"type":"FIX","url":"https://github.com/squidfunk/mkdocs-material/commit/52fb6be8aafe326419f34dc94d3211e7bbfbfb25"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/squidfunk/mkdocs-material","events":[{"introduced":"f151f71eea8d004102a11f5d47fa1783a0de7461"},{"fixed":"52fb6be8aafe326419f34dc94d3211e7bbfbfb25"},{"fixed":"b3e6dd886a974aa8200759ecfd7db28c598a2894"}],"database_specific":{"extracted_events":[{"introduced":"7.2.0"},{"fixed":"9.7.7"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["9.7.6","9.7.5","9.7.4","9.7.3","9.7.2","9.7.1","9.7.0","9.6.23","9.6.22","9.6.21","9.6.20","9.6.19","9.6.18","9.6.17","9.6.16","9.6.15","9.6.14","9.6.13","9.6.12","9.6.11","9.6.10","9.6.9","9.6.8","9.6.7","9.6.6","9.6.5","9.6.4","9.6.3","9.6.2","9.6.1","9.6.0","9.5.50","9.5.49","9.5.48","9.5.47","9.5.46","9.5.45","9.5.44","9.5.43","9.5.42","9.5.41","9.5.40","9.5.39","9.5.38","9.5.37","9.5.36","9.5.35","9.5.34","9.5.33","9.5.32","9.5.31","9.5.30","9.5.29","9.5.28","9.5.27","9.5.26","9.5.25","9.5.24","9.5.23","9.5.22","9.5.21","9.5.20","9.5.19","9.5.18","9.5.17","9.5.16","9.5.15","9.5.14","9.5.13","9.5.12","9.5.11","9.5.10","9.5.9","9.5.8","9.5.7","9.5.6","9.5.5","9.5.4","9.5.3","9.5.2","9.5.1","9.5.0","9.4.14","9.4.13","9.4.12","9.4.11","9.4.10","9.4.9","9.4.8","9.4.7","9.4.6","9.4.5","9.4.4","9.4.3","9.4.2","9.4.1","9.4.0","9.3.2","9.3.1","9.3.0","9.2.8","9.2.7","9.2.6","9.2.5","9.2.4","9.2.3","9.2.2","9.2.1","9.2.0","9.1.21","9.1.20","9.1.19","9.1.18","9.1.17","9.1.16","9.1.15","9.1.14","9.1.13","9.1.12","9.1.11","9.1.10","9.1.9","9.1.8","9.1.7","9.1.6","9.1.5","9.1.4","9.1.3","9.1.2","9.1.1","9.1.0","9.0.14","9.0.13","9.0.12","9.0.11","9.0.10","9.0.9","9.0.8","9.0.7","9.0.6","9.0.5","9.0.4","9.0.3","9.0.2","9.0.1","9.0.0","8.5.11","8.5.10","8.5.9","8.5.8","8.5.7","8.5.6","8.5.5","8.5.4","8.5.3","8.5.2","8.5.1","8.5.0","8.4.4","8.4.3","8.4.2","8.4.1","8.4.0","8.4.0rc1","8.3.9","8.3.8","8.3.7","8.3.6","8.3.5","8.3.4","8.3.3","8.3.2","8.3.1","8.3.0","8.2.16","8.2.15","8.2.14","8.2.13","8.2.12","8.2.11","8.2.10","8.2.9","8.2.8","8.2.7","8.2.6","8.2.5","8.2.4","8.2.3","8.2.2","8.2.1","8.2.0","8.1.11","8.1.10","8.1.9","8.1.8","8.1.7","8.1.6","8.1.5","8.1.4","8.1.3","8.1.2","8.1.1","8.1.0","8.0.5","8.0.4","8.0.3","8.0.2","8.0.1","8.0.0","7.3.6","7.3.5","7.3.4","7.3.3","7.3.2","7.3.1","7.3.0","7.2.8","7.2.7","7.2.6","7.2.5","7.2.4","7.2.3","7.2.2","7.2.1","7.2.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-73295.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}]}