{"id":"DEBIAN-CVE-2026-73295","details":"Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/templates/assets/javascripts/components/search/suggest/index.ts contains a DOM-based cross-site scripting vulnerability in the optional search.suggest feature that allows a crafted q URL parameter to execute JavaScript in a documentation site's origin after user interaction. This issue is fixed in version 9.7.7.","modified":"2026-09-10T08:47:21.106035144Z","published":"2026-08-12T17:17:32.637Z","upstream":["CVE-2026-73295"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-73295"}],"affected":[{"package":{"name":"mkdocs-material","ecosystem":"Debian:12","purl":"pkg:deb/debian/mkdocs-material?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["8.2.5-1","9.4.0-1","9.4.0-1.1","9.4.0-2","9.4.0-3","9.5.18-1","9.5.49-1","9.5.50-1","9.6.1-1","9.6.2-1","9.6.4-1","9.6.4-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-73295.json"}},{"package":{"name":"mkdocs-material","ecosystem":"Debian:13","purl":"pkg:deb/debian/mkdocs-material?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["9.6.4-1","9.6.4-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-73295.json"}},{"package":{"name":"mkdocs-material","ecosystem":"Debian:14","purl":"pkg:deb/debian/mkdocs-material?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["9.6.4-1","9.6.4-2"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-73295.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N"}]}