Impact
Material for MkDocs 7.2.0 through 9.7.6 contains a DOM-based cross-site scripting vulnerability in the optional search.suggest feature. A crafted q URL parameter could execute JavaScript in the documentation site's origin after user interaction.
Patches
The issue is fixed in Material for MkDocs 9.7.7. Users should upgrade to 9.7.7 or later.
Workarounds
Sites unable to upgrade should disable the search.suggest feature.
References
Impact
Material for MkDocs 7.2.0 through 9.7.6 contains a DOM-based cross-site scripting vulnerability in the optional
search.suggestfeature. A craftedqURL parameter could execute JavaScript in the documentation site's origin after user interaction.Patches
The issue is fixed in Material for MkDocs 9.7.7. Users should upgrade to 9.7.7 or later.
Workarounds
Sites unable to upgrade should disable the
search.suggestfeature.References