{"id":"CVE-2020-12827","aliases":["GHSA-4hch-r9xf-6vfr"],"url":"https://o3.security/vulnerability/CVE-2020-12827","summary":"MJML vulnerable to path traversal","details":"MJML prior to 4.6.3 contains a path traversal vulnerability when processing the mj-include directive within an MJML document.","published":"2020-06-17T14:15:10.523Z","modified":"2026-07-08T19:03:17.589701Z","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":2,"affectedPackages":[{"ecosystem":"npm","name":"mjml","fixedVersion":"4.6.3"}],"fix":{"url":"https://github.com/mjmlio/mjml/commit/30e29ed2cdaec8684d60a6d12ea07b611c765a12","label":"mjmlio/mjml@30e29ed"},"references":[{"type":"WEB","url":"https://rcesecurity.com"},{"type":"ADVISORY","url":"https://github.com/mjmlio/mjml/releases/tag/v4.6.3"},{"type":"ADVISORY","url":"https://mjml.io/community"},{"type":"ADVISORY","url":"https://twitter.com/mjmlio"},{"type":"FIX","url":"https://github.com/mjmlio/mjml/commit/30e29ed2cdaec8684d60a6d12ea07b611c765a12"},{"type":"EVIDENCE","url":"http://packetstormsecurity.com/files/158111/MJML-4.6.2-Path-Traversal.html"},{"type":"EVIDENCE","url":"http://seclists.org/fulldisclosure/2020/Jun/23"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T19:03:17.589701Z"}}