Описание
mkdocs-include-markdown-plugin susceptible to unvalidated input colliding with substitution placeholders
Impact
CWE-20: Improper Input Validation Low impact
Patches
Patched in v7.1.8 (commit https://github.com/mondeja/mkdocs-include-markdown-plugin/commit/7466d67aa0de8ffbc427204ad2475fed07678915)
Workarounds
No
Ссылки
- https://github.com/mondeja/mkdocs-include-markdown-plugin/security/advisories/GHSA-v39m-5m9j-m9w9
- https://nvd.nist.gov/vuln/detail/CVE-2025-59940
- https://github.com/mondeja/mkdocs-include-markdown-plugin/issues/274
- https://github.com/mondeja/mkdocs-include-markdown-plugin/pull/277
- https://github.com/mondeja/mkdocs-include-markdown-plugin/commit/7466d67aa0de8ffbc427204ad2475fed07678915
Пакеты
Наименование
mkdocs-include-markdown-plugin
pip
Затронутые версииВерсия исправления
< 7.1.8
7.1.8
Связанные уязвимости
CVSS3: 6.5
nvd
4 месяца назад
mkdocs-include-markdown-plugin is an Mkdocs Markdown includer plugin. In versions 7.1.7 and below, there is a vulnerability where unvalidated input can collide with substitution placeholders. This issue is fixed in version 7.1.8.