{"id":"PYSEC-2026-4108","summary":"MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers","details":"### Impact\nWhen reading a suitably crafted PRX or STX file, MPXJ can be made to write files to arbitrary locations in the file system.\n\n### Patches\nThis issue is addressed in MPXJ version 16.5.0.\n\n### Workarounds\nDo not read PRX or STX files from untrusted sources.","aliases":["CVE-2026-65829","GHSA-7952-gx68-cjqr"],"modified":"2026-10-01T17:45:10.038217678Z","published":"2026-10-01T16:38:34.692777Z","references":[{"type":"WEB","url":"https://github.com/joniles/mpxj/security/advisories/GHSA-7952-gx68-cjqr"},{"type":"WEB","url":"https://github.com/joniles/mpxj/commit/4347315afab1ef5a2907978a754fbc5b0ff58e6f"},{"type":"PACKAGE","url":"https://github.com/joniles/mpxj"},{"type":"WEB","url":"https://github.com/joniles/mpxj/releases/tag/v16.5.0"},{"type":"PACKAGE","url":"https://pypi.org/project/mpxj"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7952-gx68-cjqr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-65829"}],"affected":[{"package":{"name":"mpxj","ecosystem":"PyPI","purl":"pkg:pypi/mpxj"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.3.0"},{"fixed":"16.5.0"}]}],"versions":["10.0.0","10.0.1","10.0.2","10.0.3","10.0.4","10.0.5","10.1.0","10.10.0","10.11.0","10.12.0","10.13.0","10.14.0","10.14.1","10.15.0","10.16.0","10.16.1","10.16.2","10.2.0","10.3.0","10.4.0","10.5.0","10.6.0","10.6.1","10.6.2","10.7.0","10.8.0","10.9.0","10.9.1","11.0.0","11.1.0","11.2.0","11.3.0","11.3.1","11.3.2","11.4.0","11.5.0","11.5.1","11.5.2","11.5.3","11.5.4","12.0.0","12.0.1","12.0.2","12.1.1","12.1.2","12.1.3","12.10.0","12.10.1","12.10.2","12.10.3","12.2.0","12.3.0","12.4.0","12.5.0","12.6.0","12.7.0","12.8.0","12.8.1","12.9.0","12.9.1","12.9.2","12.9.3","13.0.0","13.0.1","13.0.2","13.1.0","13.10.0","13.11.0","13.12.0","13.2.0","13.2.1","13.3.0","13.3.1","13.4.0","13.4.1","13.4.2","13.5.0","13.5.1","13.6.0","13.7.0","13.8.0","13.9.0","14.0.0","14.1.0","14.2.0","14.3.0","14.3.1","14.3.2","14.3.3","14.3.4","14.3.5","14.4.0","14.5.0","14.5.1","14.5.2","15.0.0","15.1.0","15.2.0","15.3.0","15.3.1","16.0.0","16.1.0","16.2.0","16.3.0","16.4.0","16.4.1","9.0.0","9.1.0","9.2.0","9.2.1","9.2.2","9.2.3","9.2.4","9.2.5","9.2.6","9.3.0","9.3.1","9.4.0","9.5.0","9.5.1","9.5.2","9.6.0","9.7.0","9.8.0","9.8.1","9.8.2","9.8.3"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/mpxj/PYSEC-2026-4108.yaml"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}