Junglewise Threat Intelligence

CVE-2025-67898: MJML directory traversal in mj-include

CVE-2025-67898 · Severity: medium · CVSS 4.5 · Published 2025-12-15

Vendors: npm.

Executive brief

MJML is a framework for building responsive emails. A flaw in the mj-include feature allows attackers to discover whether files exist on the server and potentially read file contents, which could expose sensitive configuration files or other data. This is a regression from a prior security fix that did not fully address the underlying issue. Attackers do not need authentication to exploit this vulnerability.

Technical details

The vulnerability is a directory traversal flaw (CWE-36) in MJML's mj-include element that was incompletely patched in a previous fix for CVE-2020-12827. The vulnerability occurs because the ignoreIncludes configuration option, which is intended to prevent remote includes, defaults to false rather than true. An unauthenticated attacker with network access can craft malicious MJML documents containing mj-include elements with path traversal sequences (e.g., ../../etc/passwd) to test file existence or, in the case of type="css", read file contents. The attack requires no special preconditions beyond the ability to submit MJML to a rendering service. The fix, merged in commit 517b376b, changes the default value of ignoreIncludes to true and was released in version 5.0.0-alpha.9.

Affected products

  • MJML MJML before 5.0.0-alpha.9

Timeline

  • 2025-12-15: disclosed: Advisory published
  • 2026-01-15: other: Fix commit authored
  • 2026-01-19: other: Fix commit merged into fix/replace-html-minifier branch
  • 5.0.0-alph: patched: Fixed version released

References

Related threats