{"id":"CVE-2024-49771","aliases":["GHSA-j945-c44v-97g6","PYSEC-2026-1681"],"url":"https://o3.security/vulnerability/CVE-2024-49771","summary":"MPXJ has a Potential Path Traversal Vulnerability","details":"### Impact\nThe patch for the historical vulnerability CVE-2020-35460 in MPXJ is incomplete as there is still a possibility that a malicious path could be constructed which would not be picked up by the original fix and allow files to be written to arbitrary locations.\n\n### Patches\nThe issue is addressed in MPXJ version 13.5.1\n\n### Workarounds\nDo not pass zip files to MPXJ.\n\n### References\nN/A\n\n### Credits\nIssue report and patch provided by yyjLF and sprinkle","published":"2024-10-28T16:57:43.271Z","modified":"2026-08-12T15:15:40.054667Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"net.sf.mpxj:mpxj","fixedVersion":"13.5.1"},{"ecosystem":"NuGet","name":"net.sf.mpxj","fixedVersion":"13.5.1"},{"ecosystem":"NuGet","name":"net.sf.mpxj-for-csharp","fixedVersion":"13.5.1"},{"ecosystem":"NuGet","name":"net.sf.mpxj-for-vb","fixedVersion":"13.5.1"},{"ecosystem":"NuGet","name":"MPXJ.Net","fixedVersion":"13.5.1"},{"ecosystem":"PyPI","name":"mpxj","fixedVersion":"13.5.1"},{"ecosystem":"RubyGems","name":"mpxj","fixedVersion":"13.5.1"}],"fix":{"url":"https://github.com/joniles/mpxj/commit/8002802890dfdc8bc74259f37e053e15b827eea0","label":"joniles/mpxj@8002802"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/49xxx/CVE-2024-49771.json"},{"type":"ADVISORY","url":"https://github.com/joniles/mpxj/security/advisories/GHSA-j945-c44v-97g6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-49771"},{"type":"FIX","url":"https://github.com/joniles/mpxj/commit/8002802890dfdc8bc74259f37e053e15b827eea0"},{"type":"PACKAGE","url":"https://github.com/joniles/mpxj"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/mpxj/CVE-2024-49771.yml"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T15:15:40.054667Z"}}