PT-2025-51175 · Mjml · Mjml

Published

2025-12-14

·

Updated

2025-12-15

·

CVE-2025-67898

CVSS v3.1

4.5

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions MJML versions through 4.18.0
Description The software contains a directory traversal flaw within the mj-include functionality. This allows an attacker to check for the existence of files and, in cases where the type is set to "css", read files. This issue stems from an incomplete resolution of a previously identified problem.
Recommendations Update to a version beyond 4.18.0.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-67898
GHSA-45H5-66JX-R2WF

Affected Products

Mjml