{"id":"CVE-2025-59940","title":"mkdocs-include-markdown-plugin: mkdocs-include-markdown-plugin susceptible to unvalidated input colliding with substitution placeholders (C…","summary":"There is an improper input validation flaw in the python `mkdocs-include-markdown-plugin` package. Under certain conditions placeholders are not properly validated and may collide with other data elements resulting in inconsistent output.","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","cvssSource":"vendor","cwe":"CWE-20","vendor":"Red Hat","product":"Multicluster Engine for Kubernetes","affected":["assisted_installer_for_red_hat_openshift_container_platform 2","multicluster_engine_for_kubernetes","openshift_container_platform 4"],"patched":["mkdocs-include-markdown-plugin 7.1.8"],"published":"2025-09-29","updated":"2026-09-23","sourceUpdated":"2026-09-23T03:37:46+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59940.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59940.json"},{"url":"https://access.redhat.com/security/cve/CVE-2025-59940"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2400372"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-59940"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59940"},{"url":"https://github.com/mondeja/mkdocs-include-markdown-plugin/commit/7466d67aa0de8ffbc427204ad2475fed07678915"},{"url":"https://github.com/mondeja/mkdocs-include-markdown-plugin/issues/274"},{"url":"https://github.com/mondeja/mkdocs-include-markdown-plugin/pull/277"},{"url":"https://github.com/mondeja/mkdocs-include-markdown-plugin/security/advisories/GHSA-v39m-5m9j-m9w9"},{"url":"https://github.com/mondeja/mkdocs-include-markdown-plugin"}],"tags":["csaf","vex","red-hat","osv","pip"],"epss":0.00341,"epssPercentile":0.27746,"aliases":["GHSA-v39m-5m9j-m9w9","PYSEC-2026-1632"],"ecosystem":"pip","ingestedAt":"2026-07-08T18:25:53.057Z","slug":"CVE-2025-59940","body":"## Overview\n\nThere is an improper input validation flaw in the python `mkdocs-include-markdown-plugin` package. Under certain conditions placeholders are not properly validated and may collide with other data elements resulting in inconsistent output.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Assisted Installer for Red Hat OpenShift Container Platform 2, Multicluster Engine for Kubernetes, Red Hat OpenShift Container Platform 4 · no fix planned: Assisted Installer for Red Hat OpenShift Container Platform 2, Multicluster Engine for Kubernetes, Red Hat OpenShift Container Platform 4 · updated 2026-09-23 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-59940.json)\n\n**mkdocs-include-markdown-plugin: mkdocs-include-markdown-plugin susceptible to unvalidated input colliding with substitution placeholders** — rated Moderate by Red Hat. Released 2025-09-29, updated 2026-09-23.\n\nAffected:\n\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- Multicluster Engine for Kubernetes\n- Red Hat OpenShift Container Platform 4\n\nNo fix planned:\n\n- Assisted Installer for Red Hat OpenShift Container Platform 2\n- Multicluster Engine for Kubernetes\n- Red Hat OpenShift Container Platform 4\n\n## Remediation\n\nFix deferred\n\nWorkarounds / mitigations:\n\n- Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.\n\n## Package advisory (CVE-2025-59940)\n\nAffected packages:\n\n- `mkdocs-include-markdown-plugin < 7.1.8`\n\nPatched in:\n\n- `mkdocs-include-markdown-plugin 7.1.8`\n\nSource: https://osv.dev/vulnerability/GHSA-v39m-5m9j-m9w9","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}