Security Advisory

CVE-2025-67898

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-12-14 22:01:05
Last updated 2025-12-15 16:24:49
Assigner mitre
State PUBLISHED

Description

MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827.