CVE-2025-59940: Mondeja Mkdocs-Include-Markdown-Plugin

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

mkdocs-include-markdown-plugin is an Mkdocs Markdown includer plugin. In versions 7.1.7 and below, there is a vulnerability where unvalidated input can collide with substitution placeholders. This issue is fixed in version 7.1.8.

Affected products

  • Mondeja Mkdocs-Include-Markdown-Plugin: before 7.1.8 (fixed in 7.1.8)

Published 2025-09-29. Last modified 2026-10-09.