VDB
Sign up
HIGH7.2

GHSA-4hch-r9xf-6vfr

MJML vulnerable to path traversal

Quick fix

GHSA-4hch-r9xf-6vfr — mjml: upgrade to the fixed version with the command below.

npm install mjml@4.6.3

Details

MJML prior to 4.6.3 contains a path traversal vulnerability when processing the `mj-include` directive within an MJML document.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mjml
Introduced in: 0Fixed in: 4.6.3
Fixnpm install mjml@4.6.3

References