{"id":"GHSA-45h5-66jx-r2wf","summary":"MJML allows mj-include directory traversal due to an incomplete fix for CVE-2020-12827","details":"MJML before 5.0.0-alpha.9 allows mj-include directory traversal to test file existence and (in the type=\"css\" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827.","aliases":["CVE-2025-67898"],"modified":"2026-09-10T03:50:31.395785465Z","published":"2025-12-15T00:30:25Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2025-12-17T18:12:02Z","nvd_published_at":"2025-12-14T22:15:36Z","cwe_ids":["CWE-36"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-12827"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-67898"},{"type":"WEB","url":"https://github.com/mjmlio/mjml/issues/3018"},{"type":"WEB","url":"https://github.com/mjmlio/mjml/pull/3033"},{"type":"WEB","url":"https://github.com/mjmlio/mjml/commit/517b376b068e71c713ec4bb4ef9e5b0b7235b8ce"},{"type":"PACKAGE","url":"https://github.com/mjmlio/mjml"}],"affected":[{"package":{"name":"mjml","ecosystem":"npm","purl":"pkg:npm/mjml"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"5.0.0-alpha.9"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/12/GHSA-45h5-66jx-r2wf/GHSA-45h5-66jx-r2wf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:N/A:L"}]}