GHSA-45h5-66jx-r2wfMediumCVSS 4.5
MJML allows mj-include directory traversal due to an incomplete fix for CVE-2020-12827
🔗 CVE IDs covered (1)
📋 Description
MJML before 5.0.0-alpha.9 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827.
🎯 Affected products1
- npm/mjml:< 5.0.0-alpha.9
🔗 References (6)
- https://nvd.nist.gov/vuln/detail/CVE-2025-67898
- https://github.com/mjmlio/mjml/issues/3018
- https://nvd.nist.gov/vuln/detail/CVE-2020-12827
- https://github.com/mjmlio/mjml/pull/3033
- https://github.com/mjmlio/mjml/commit/517b376b068e71c713ec4bb4ef9e5b0b7235b8ce
- https://github.com/advisories/GHSA-45h5-66jx-r2wf