chore(deps): update dependency mkdocs-material to v9.7.7 [security] #202

Open
Renovate wants to merge 1 commit from renovate/pypi-mkdocs-material-vulnerability into main
Collaborator

This PR contains the following updates:

Package Change Age Confidence
mkdocs-material (changelog) 9.7.69.7.7 age confidence

Material for MkDocs: DOM XSS in search suggestions via query parameter

CVE-2026-73295 / GHSA-xvg9-69gf-fjrf / PYSEC-2026-3864

More information

Details

Impact

Material for MkDocs 7.2.0 through 9.7.6 contains a DOM-based cross-site scripting vulnerability in the optional search.suggest feature. A crafted q URL parameter could execute JavaScript in the documentation site's origin after user interaction.

Patches

The issue is fixed in Material for MkDocs 9.7.7. Users should upgrade to 9.7.7 or later.

Workarounds

Sites unable to upgrade should disable the search.suggest feature.

Severity

  • CVSS Score: 5.4 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

References

This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).


Material for MkDocs: DOM XSS in search suggestions via query parameter

CVE-2026-73295 / GHSA-xvg9-69gf-fjrf / PYSEC-2026-3864

More information

Details

Impact

Material for MkDocs 7.2.0 through 9.7.6 contains a DOM-based cross-site scripting vulnerability in the optional search.suggest feature. A crafted q URL parameter could execute JavaScript in the documentation site's origin after user interaction.

Patches

The issue is fixed in Material for MkDocs 9.7.7. Users should upgrade to 9.7.7 or later.

Workarounds

Sites unable to upgrade should disable the search.suggest feature.

Severity

  • CVSS Score: 5.4 / 10 (Medium)
  • Vector String: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

References

This data is provided by OSV and the PyPI Advisory Database (CC-BY 4.0).


Release Notes

squidfunk/mkdocs-material (mkdocs-material)

v9.7.7: mkdocs-material-9.7.7

Compare Source

[!WARNING]

Material for MkDocs is approaching end of life

Material for MkDocs is scheduled to reach end of life on November 5, 2026. Until then, maintenance is limited to critical bug fixes and security updates. After this date, the project will remain available on PyPI and GitHub, but no further maintenance is planned except in exceptional circumstances.

For users looking for a long-term, actively developed successor, we're building Zensical – a next-generation static site generator designed for technical documentation. If you're planning a new documentation project or evaluating your long-term options, we invite you to take a look.

Organizations requiring support beyond this date are welcome to get in touch to discuss available options.

Read the full announcement on our blog

Changes

  • Fixed a DOM-based XSS vulnerability in search suggestions

Thanks to @​p- for responsibly reporting this issue.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [mkdocs-material](https://github.com/squidfunk/mkdocs-material) ([changelog](https://squidfunk.github.io/mkdocs-material/changelog/)) | `9.7.6` → `9.7.7` | ![age](https://developer.mend.io/api/mc/badges/age/pypi/mkdocs-material/9.7.7?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/pypi/mkdocs-material/9.7.6/9.7.7?slim=true) | --- ### Material for MkDocs: DOM XSS in search suggestions via query parameter [CVE-2026-73295](https://nvd.nist.gov/vuln/detail/CVE-2026-73295) / [GHSA-xvg9-69gf-fjrf](https://github.com/advisories/GHSA-xvg9-69gf-fjrf) / PYSEC-2026-3864 <details> <summary>More information</summary> #### Details ##### Impact Material for MkDocs 7.2.0 through 9.7.6 contains a DOM-based cross-site scripting vulnerability in the optional `search.suggest` feature. A crafted `q` URL parameter could execute JavaScript in the documentation site's origin after user interaction. ##### Patches The issue is fixed in Material for MkDocs 9.7.7. Users should upgrade to 9.7.7 or later. ##### Workarounds Sites unable to upgrade should disable the `search.suggest` feature. #### Severity - CVSS Score: 5.4 / 10 (Medium) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N` #### References - [https://github.com/squidfunk/mkdocs-material/security/advisories/GHSA-xvg9-69gf-fjrf](https://github.com/squidfunk/mkdocs-material/security/advisories/GHSA-xvg9-69gf-fjrf) - [https://nvd.nist.gov/vuln/detail/CVE-2026-73295](https://nvd.nist.gov/vuln/detail/CVE-2026-73295) - [https://github.com/squidfunk/mkdocs-material/commit/52fb6be8aafe326419f34dc94d3211e7bbfbfb25](https://github.com/squidfunk/mkdocs-material/commit/52fb6be8aafe326419f34dc94d3211e7bbfbfb25) - [https://github.com/squidfunk/mkdocs-material](https://github.com/squidfunk/mkdocs-material) - [https://github.com/squidfunk/mkdocs-material/releases/tag/9.7.7](https://github.com/squidfunk/mkdocs-material/releases/tag/9.7.7) This data is provided by [OSV](https://osv.dev/vulnerability/GHSA-xvg9-69gf-fjrf) and the [GitHub Advisory Database](https://github.com/github/advisory-database) ([CC-BY 4.0](https://github.com/github/advisory-database/blob/main/LICENSE.md)). </details> --- ### Material for MkDocs: DOM XSS in search suggestions via query parameter [CVE-2026-73295](https://nvd.nist.gov/vuln/detail/CVE-2026-73295) / [GHSA-xvg9-69gf-fjrf](https://github.com/advisories/GHSA-xvg9-69gf-fjrf) / PYSEC-2026-3864 <details> <summary>More information</summary> #### Details ##### Impact Material for MkDocs 7.2.0 through 9.7.6 contains a DOM-based cross-site scripting vulnerability in the optional `search.suggest` feature. A crafted `q` URL parameter could execute JavaScript in the documentation site's origin after user interaction. ##### Patches The issue is fixed in Material for MkDocs 9.7.7. Users should upgrade to 9.7.7 or later. ##### Workarounds Sites unable to upgrade should disable the `search.suggest` feature. #### Severity - CVSS Score: 5.4 / 10 (Medium) - Vector String: `CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N` #### References - [https://github.com/squidfunk/mkdocs-material/security/advisories/GHSA-xvg9-69gf-fjrf](https://github.com/squidfunk/mkdocs-material/security/advisories/GHSA-xvg9-69gf-fjrf) - [https://nvd.nist.gov/vuln/detail/CVE-2026-73295](https://nvd.nist.gov/vuln/detail/CVE-2026-73295) - [https://github.com/squidfunk/mkdocs-material/commit/52fb6be8aafe326419f34dc94d3211e7bbfbfb25](https://github.com/squidfunk/mkdocs-material/commit/52fb6be8aafe326419f34dc94d3211e7bbfbfb25) - [https://github.com/squidfunk/mkdocs-material](https://github.com/squidfunk/mkdocs-material) - [https://github.com/squidfunk/mkdocs-material/releases/tag/9.7.7](https://github.com/squidfunk/mkdocs-material/releases/tag/9.7.7) - [https://pypi.org/project/mkdocs-material](https://pypi.org/project/mkdocs-material) - [https://github.com/advisories/GHSA-xvg9-69gf-fjrf](https://github.com/advisories/GHSA-xvg9-69gf-fjrf) This data is provided by [OSV](https://osv.dev/vulnerability/PYSEC-2026-3864) and the [PyPI Advisory Database](https://github.com/pypa/advisory-database) ([CC-BY 4.0](https://github.com/pypa/advisory-database/blob/main/LICENSE)). </details> --- ### Release Notes <details> <summary>squidfunk/mkdocs-material (mkdocs-material)</summary> ### [`v9.7.7`](https://github.com/squidfunk/mkdocs-material/releases/tag/9.7.7): mkdocs-material-9.7.7 [Compare Source](https://github.com/squidfunk/mkdocs-material/compare/9.7.6...9.7.7) > \[!WARNING] > > **Material for MkDocs is approaching end of life** > > Material for MkDocs is scheduled to reach end of life on November 5, 2026. Until then, maintenance is limited to critical bug fixes and security updates. After this date, the project will remain available on PyPI and GitHub, but no further maintenance is planned except in exceptional circumstances. > > For users looking for a long-term, actively developed successor, we're building [Zensical] – a next-generation static site generator designed for technical documentation. If you're planning a new documentation project or evaluating your long-term options, we invite you to take a look. > > Organizations requiring support beyond this date are welcome to get in touch to discuss available options. > > [Read the full announcement on our blog] [Zensical]: https://zensical.org [Read the full announcement on our blog]: https://squidfunk.github.io/mkdocs-material/blog/2025/11/05/zensical/ #### Changes - Fixed a DOM-based XSS vulnerability in search suggestions > Thanks to [@&#8203;p-](https://github.com/p-) for responsibly reporting this issue. </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC41Mi4xIiwidXBkYXRlZEluVmVyIjoiNDQuNjUuNSIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOltdfQ==-->
chore(deps): update dependency mkdocs-material to v9.7.7 [security]
All checks were successful
Actions / Build Documentation (pull_request) Successful in 1m0s
Actions / Lint (pull_request) Successful in 1m6s
Actions / Ensure Cogs Load (pull_request) Successful in 4m32s
dd723d7608
Renovate force-pushed renovate/pypi-mkdocs-material-vulnerability from dd723d7608
All checks were successful
Actions / Build Documentation (pull_request) Successful in 1m0s
Actions / Lint (pull_request) Successful in 1m6s
Actions / Ensure Cogs Load (pull_request) Successful in 4m32s
to 0e9556b7fb
All checks were successful
Actions / Build Documentation (pull_request) Successful in 55s
Actions / Lint (pull_request) Successful in 1m2s
Actions / Ensure Cogs Load (pull_request) Successful in 4m27s
2026-09-03 22:05:39 -04:00
Compare
Renovate force-pushed renovate/pypi-mkdocs-material-vulnerability from 0e9556b7fb
All checks were successful
Actions / Build Documentation (pull_request) Successful in 55s
Actions / Lint (pull_request) Successful in 1m2s
Actions / Ensure Cogs Load (pull_request) Successful in 4m27s
to 9bfc847ad1
All checks were successful
Actions / Lint (pull_request) Successful in 1m3s
Actions / Build Documentation (pull_request) Successful in 55s
Actions / Ensure Cogs Load (pull_request) Successful in 4m38s
2026-09-04 03:06:11 -04:00
Compare
Renovate force-pushed renovate/pypi-mkdocs-material-vulnerability from 9bfc847ad1
All checks were successful
Actions / Lint (pull_request) Successful in 1m3s
Actions / Build Documentation (pull_request) Successful in 55s
Actions / Ensure Cogs Load (pull_request) Successful in 4m38s
to 453df6c1a3
All checks were successful
Actions / Lint (pull_request) Successful in 1m20s
Actions / Ensure Cogs Load (pull_request) Successful in 4m16s
Actions / Build Documentation (pull_request) Successful in 52s
2026-09-06 16:05:25 -04:00
Compare
Renovate force-pushed renovate/pypi-mkdocs-material-vulnerability from 453df6c1a3
All checks were successful
Actions / Lint (pull_request) Successful in 1m20s
Actions / Ensure Cogs Load (pull_request) Successful in 4m16s
Actions / Build Documentation (pull_request) Successful in 52s
to 23a8197803
All checks were successful
Actions / Lint (pull_request) Successful in 1m1s
Actions / Build Documentation (pull_request) Successful in 53s
Actions / Ensure Cogs Load (pull_request) Successful in 4m27s
2026-09-08 10:05:42 -04:00
Compare
Renovate force-pushed renovate/pypi-mkdocs-material-vulnerability from 23a8197803
All checks were successful
Actions / Lint (pull_request) Successful in 1m1s
Actions / Build Documentation (pull_request) Successful in 53s
Actions / Ensure Cogs Load (pull_request) Successful in 4m27s
to be27011776
Some checks failed
Actions / Lint (pull_request) Successful in 1m1s
Actions / Build Documentation (pull_request) Failing after 41s
Actions / Ensure Cogs Load (pull_request) Successful in 4m10s
2026-09-09 15:05:22 -04:00
Compare
Some checks failed
Actions / Lint (pull_request) Successful in 1m1s
Required
Details
Actions / Build Documentation (pull_request) Failing after 41s
Required
Details
Actions / Ensure Cogs Load (pull_request) Successful in 4m10s
Required
Details
Some required checks were not successful.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/pypi-mkdocs-material-vulnerability:renovate/pypi-mkdocs-material-vulnerability
git switch renovate/pypi-mkdocs-material-vulnerability
Sign in to join this conversation.
No description provided.