mkdocs@0.17.0 vulnerabilities

Project documentation with Markdown.

Direct Vulnerabilities

Known vulnerabilities in the mkdocs package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Cross-site Scripting (XSS)

mkdocs is a Project documentation with Markdown.

Affected versions of this package are vulnerable to Cross-site Scripting (XSS) when using the search function in built-in themes.

How to fix Cross-site Scripting (XSS)?

Upgrade mkdocs to version 1.3.0 or higher.

[,1.3.0)
  • H
Directory Traversal

mkdocs is a Project documentation with Markdown.

Affected versions of this package are vulnerable to Directory Traversal. The mkdocs built-in dev-server allows directory traversal using the port 8000, enabling remote exploitation to obtain :sensitive information.

How to fix Directory Traversal?

Upgrade mkdocs to version 1.2.3 or higher.

[0,1.2.3)