CVE-2025-67898

MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827.
Configurations

No configuration.

History

No history.

Information

Published : 2025-12-14 22:15

Updated : 2025-12-15 18:22


NVD link : CVE-2025-67898

Mitre link : CVE-2025-67898

CVE.ORG link : CVE-2025-67898


JSON object : View

Products Affected

No product.

CWE
CWE-36

Absolute Path Traversal