CVE-2026-65829: Joniles Mpxj

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 7.3.0 until 16.5.0, reading a suitably crafted Primavera P3 PRX or SureTrak STX file can cause MPXJ to write files to arbitrary locations in the filesystem. This issue is fixed in version 16.5.0.

Affected products

  • Joniles Mpxj: from 7.3.0, before 16.5.0 (fixed in 16.5.0)

Published 2026-09-22. Last modified 2026-09-23.