HIGH7.2
GHSA-4hch-r9xf-6vfr
MJML vulnerable to path traversal
Quick fix
GHSA-4hch-r9xf-6vfr — mjml: upgrade to the fixed version with the command below.
npm install mjml@4.6.3Details
MJML prior to 4.6.3 contains a path traversal vulnerability when processing the `mj-include` directive within an MJML document.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2020-12827[ADVISORY]
- https://github.com/mjmlio/mjml/commit/30e29ed2cdaec8684d60a6d12ea07b611c765a12[WEB]
- https://github.com/mjmlio/mjml[PACKAGE]
- https://github.com/mjmlio/mjml/releases/tag/v4.6.3[WEB]
- http://packetstormsecurity.com/files/158111/MJML-4.6.2-Path-Traversal.html[WEB]
- http://seclists.org/fulldisclosure/2020/Jun/23[WEB]