Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-73295

Опубликовано: 12 авг. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/templates/assets/javascripts/components/search/suggest/index.ts contains a DOM-based cross-site scripting vulnerability in the optional search.suggest feature that allows a crafted q URL parameter to execute JavaScript in a documentation site's origin after user interaction. This issue is fixed in version 9.7.7.

A flaw was found in Material for MkDocs. A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the search suggestion feature. A remote attacker could exploit this by crafting a malicious URL with a specially designed query parameter. After user interaction, this could lead to the execution of arbitrary JavaScript code in the context of the documentation site, potentially resulting in information disclosure or other client-side attacks.

Отчет

This Moderate DOM-based cross-site scripting flaw in Material for MkDocs requires user interaction with a specially crafted URL. The vulnerability affects an optional search suggestion feature, which limits its immediate impact on typical Red Hat deployments where this feature may not be enabled by default.

Меры по смягчению последствий

To mitigate this issue, disable the optional search.suggest feature in Material for MkDocs if it is not required for your deployment. Consult the Material for MkDocs documentation for specific configuration instructions on how to disable this feature. Disabling this feature may impact the search functionality of your documentation site.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Certification Program for Red Hat Enterprise Linux 9redhat-certification-cnfFix deferred
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Fix deferred
Red Hat Hardened Imagesgrafana12.4Not affected
Red Hat Hardened Imagesgrafana13.1Not affected
Red Hat Hardened ImagestrivyNot affected
Red Hat OpenShift Container Platform 4openshift4/ose-olm-catalogd-rhel9Fix deferred
Self-service automation portal 2ansible-automation-platform/bootc-automation-portal-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2514806mkdocs-material: Material for MkDocs: DOM-based Cross-Site Scripting via crafted URL parameter

EPSS

Процентиль: 8%
0.00185
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
16 дней назад

Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/templates/assets/javascripts/components/search/suggest/index.ts contains a DOM-based cross-site scripting vulnerability in the optional search.suggest feature that allows a crafted q URL parameter to execute JavaScript in a documentation site's origin after user interaction. This issue is fixed in version 9.7.7.

CVSS3: 5.4
nvd
16 дней назад

Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/templates/assets/javascripts/components/search/suggest/index.ts contains a DOM-based cross-site scripting vulnerability in the optional search.suggest feature that allows a crafted q URL parameter to execute JavaScript in a documentation site's origin after user interaction. This issue is fixed in version 9.7.7.

CVSS3: 5.4
debian
16 дней назад

Material for MkDocs is a powerful documentation framework built on top ...

EPSS

Процентиль: 8%
0.00185
Низкий

5.4 Medium

CVSS3