6.5
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Description
mkdocs-include-markdown-plugin is an Mkdocs Markdown includer plugin. In versions 7.1.7 and below, there is a vulnerability where unvalidated input can collide with substitution placeholders. This issue is fixed in version 7.1.8.
Basic Information
ID
CVE-2025-59940
Source
GitHub_M
Published
Sep 29, 2025 at 22:27
Affected Product
Vendor
mondeja
Product
mkdocs-include-markdown-plugin
Version
< 7.1.8
Affected Versions
mondeja mkdocs-include-markdown-plugin < 7.1.8
CWE Classification
References
- github.com /mondeja/mkdocs-include-markdown-plugin/security/advisories/GHSA-v39m-5m9j-m9w9
- github.com /mondeja/mkdocs-include-markdown-plugin/issues/274
- github.com /mondeja/mkdocs-include-markdown-plugin/pull/277
- github.com /mondeja/mkdocs-include-markdown-plugin/commit/7466d67aa0de8ffbc427204ad2475fed07678915