{"id":"PYSEC-2026-1681","summary":"MPXJ has a Potential Path Traversal Vulnerability","details":"### Impact\nThe patch for the historical vulnerability CVE-2020-35460 in MPXJ is incomplete as there is still a possibility that a malicious path could be constructed which would not be picked up by the original fix and allow files to be written to arbitrary locations.\n\n### Patches\nThe issue is addressed in MPXJ version 13.5.1\n\n### Workarounds\nDo not pass zip files to MPXJ.\n\n### References\nN/A\n\n### Credits\nIssue report and patch provided by yyjLF and sprinkle","aliases":["CVE-2024-49771","GHSA-j945-c44v-97g6"],"modified":"2026-07-07T17:47:17.650298371Z","published":"2026-07-07T14:34:43.523396Z","references":[{"type":"WEB","url":"https://github.com/joniles/mpxj/security/advisories/GHSA-j945-c44v-97g6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-49771"},{"type":"WEB","url":"https://github.com/joniles/mpxj/commit/8002802890dfdc8bc74259f37e053e15b827eea0"},{"type":"PACKAGE","url":"https://github.com/joniles/mpxj"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/mpxj/CVE-2024-49771.yml"},{"type":"PACKAGE","url":"https://pypi.org/project/mpxj"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-j945-c44v-97g6"}],"affected":[{"package":{"name":"mpxj","ecosystem":"PyPI","purl":"pkg:pypi/mpxj"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"8.3.5"},{"fixed":"13.5.1"}]}],"versions":["10.0.0","10.0.1","10.0.2","10.0.3","10.0.4","10.0.5","10.1.0","10.10.0","10.11.0","10.12.0","10.13.0","10.14.0","10.14.1","10.15.0","10.16.0","10.16.1","10.16.2","10.2.0","10.3.0","10.4.0","10.5.0","10.6.0","10.6.1","10.6.2","10.7.0","10.8.0","10.9.0","10.9.1","11.0.0","11.1.0","11.2.0","11.3.0","11.3.1","11.3.2","11.4.0","11.5.0","11.5.1","11.5.2","11.5.3","11.5.4","12.0.0","12.0.1","12.0.2","12.1.1","12.1.2","12.1.3","12.10.0","12.10.1","12.10.2","12.10.3","12.2.0","12.3.0","12.4.0","12.5.0","12.6.0","12.7.0","12.8.0","12.8.1","12.9.0","12.9.1","12.9.2","12.9.3","13.0.0","13.0.1","13.0.2","13.1.0","13.2.0","13.2.1","13.3.0","13.3.1","13.4.0","13.4.1","13.4.2","13.5.0","9.0.0","9.1.0","9.2.0","9.2.1","9.2.2","9.2.3","9.2.4","9.2.5","9.2.6","9.3.0","9.3.1","9.4.0","9.5.0","9.5.1","9.5.2","9.6.0","9.7.0","9.8.0","9.8.1","9.8.2","9.8.3"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/mpxj/PYSEC-2026-1681.yaml"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}