CVE-2025-67898: Mjml

Medium severity, CVSS 4.5. EPSS: 0.3% chance of exploitation in the next 30 days.

MJML through 4.18.0 allows mj-include directory traversal to test file existence and (in the type="css" case) read files. NOTE: this issue exists because of an incomplete fix for CVE-2020-12827.

Affected products

  • Mjml Mjml: up to and including 4.18.0

Published 2025-12-14. Last modified 2026-06-17.