Home

Description

mkdocs-include-markdown-plugin is an Mkdocs Markdown includer plugin. In versions 7.1.7 and below, there is a vulnerability where unvalidated input can collide with substitution placeholders. This issue is fixed in version 7.1.8.

PUBLISHED Reserved 2025-09-23 | Published 2025-09-29 | Updated 2025-09-30 | Assigner GitHub_M




MEDIUM: 6.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Problem types

CWE-20: Improper Input Validation

Product status

< 7.1.8
affected

References

github.com/...plugin/security/advisories/GHSA-v39m-5m9j-m9w9

github.com/mondeja/mkdocs-include-markdown-plugin/issues/274

github.com/mondeja/mkdocs-include-markdown-plugin/pull/277

github.com/...ommit/7466d67aa0de8ffbc427204ad2475fed07678915

cve.org (CVE-2025-59940)

nvd.nist.gov (CVE-2025-59940)

Download JSON