Vulnerable Library - mkdocs-material-9.5.20-pyhd8ed1ab_0.conda
A Material Design theme for mkdocs
Library home page: https://api.anaconda.org/download/conda-forge/mkdocs-material/9.5.20/noarch/mkdocs-material-9.5.20-pyhd8ed1ab_0.conda
Sample Path to Dependency File: /environment.yml
Path to vulnerable library: /home/wss-scanner/miniconda3/pkgs/mkdocs-material-9.5.20-pyhd8ed1ab_0.conda
Vulnerabilities
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2026-73295
Vulnerable Library - mkdocs-material-9.5.20-pyhd8ed1ab_0.conda
A Material Design theme for mkdocs
Library home page: https://api.anaconda.org/download/conda-forge/mkdocs-material/9.5.20/noarch/mkdocs-material-9.5.20-pyhd8ed1ab_0.conda
Sample Path to Dependency File: /environment.yml
Path to vulnerable library: /home/wss-scanner/miniconda3/pkgs/mkdocs-material-9.5.20-pyhd8ed1ab_0.conda
Dependency Hierarchy:
- ❌ mkdocs-material-9.5.20-pyhd8ed1ab_0.conda (Vulnerable Library)
Found in base branch: develop
Vulnerability Details
Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/templates/assets/javascripts/components/search/suggest/index.ts contains a DOM-based cross-site scripting vulnerability in the optional search.suggest feature that allows a crafted q URL parameter to execute JavaScript in a documentation site's origin after user interaction. This issue is fixed in version 9.7.7.
Publish Date: 2026-08-12
URL: CVE-2026-73295
CVSS 3 Score Details (5.4)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
For more information on CVSS3 Scores, click here.
Suggested Fix
Type: Upgrade version
Origin: GHSA-xvg9-69gf-fjrf
Release Date: 2026-08-12
Fix Resolution: mkdocs-material - 9.7.7,mkdocs-material - 9.7.7,https://github.com/squidfunk/mkdocs-material.git - 9.7.7
Step up your Open Source Security Game with Mend here
A Material Design theme for mkdocs
Library home page: https://api.anaconda.org/download/conda-forge/mkdocs-material/9.5.20/noarch/mkdocs-material-9.5.20-pyhd8ed1ab_0.conda
Sample Path to Dependency File: /environment.yml
Path to vulnerable library: /home/wss-scanner/miniconda3/pkgs/mkdocs-material-9.5.20-pyhd8ed1ab_0.conda
Vulnerabilities
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
Vulnerable Library - mkdocs-material-9.5.20-pyhd8ed1ab_0.conda
A Material Design theme for mkdocs
Library home page: https://api.anaconda.org/download/conda-forge/mkdocs-material/9.5.20/noarch/mkdocs-material-9.5.20-pyhd8ed1ab_0.conda
Sample Path to Dependency File: /environment.yml
Path to vulnerable library: /home/wss-scanner/miniconda3/pkgs/mkdocs-material-9.5.20-pyhd8ed1ab_0.conda
Dependency Hierarchy:
Found in base branch: develop
Vulnerability Details
Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearchSuggest function in src/templates/assets/javascripts/components/search/suggest/index.ts contains a DOM-based cross-site scripting vulnerability in the optional search.suggest feature that allows a crafted q URL parameter to execute JavaScript in a documentation site's origin after user interaction. This issue is fixed in version 9.7.7.
Publish Date: 2026-08-12
URL: CVE-2026-73295
CVSS 3 Score Details (5.4)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: Required
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: Low
- Integrity Impact: Low
- Availability Impact: None
For more information on CVSS3 Scores, click here.Suggested Fix
Type: Upgrade version
Origin: GHSA-xvg9-69gf-fjrf
Release Date: 2026-08-12
Fix Resolution: mkdocs-material - 9.7.7,mkdocs-material - 9.7.7,https://github.com/squidfunk/mkdocs-material.git - 9.7.7
Step up your Open Source Security Game with Mend here