CVE-2022-50897: Mpdf Project Mpdf

Medium severity, CVSS 5.5. EPSS: 0.6% chance of exploitation in the next 30 days.

mPDF 7.0 contains a local file inclusion vulnerability that allows attackers to read arbitrary system files by manipulating annotation file parameters. Attackers can generate URL-encoded or base64 payloads to include local files through crafted annotation content with file path specifications.

Affected products

Published 2026-01-13. Last modified 2026-06-17.