Material for MkDocs: DOM XSS in search suggestions via query parameter
Moderate severity
GitHub Reviewed
Published
Jul 17, 2026
in
squidfunk/mkdocs-material
•
Updated Sep 3, 2026
Description
Published by the National Vulnerability Database
Aug 12, 2026
Published to the GitHub Advisory Database
Sep 3, 2026
Reviewed
Sep 3, 2026
Last updated
Sep 3, 2026
Impact
Material for MkDocs 7.2.0 through 9.7.6 contains a DOM-based cross-site scripting vulnerability in the optional
search.suggestfeature. A craftedqURL parameter could execute JavaScript in the documentation site's origin after user interaction.Patches
The issue is fixed in Material for MkDocs 9.7.7. Users should upgrade to 9.7.7 or later.
Workarounds
Sites unable to upgrade should disable the
search.suggestfeature.References