High severity7.2NVD Advisory· Published Jun 17, 2020· Updated Jun 17, 2026
CVE-2020-12827
CVE-2020-12827
Description
MJML prior to 4.6.3 contains a path traversal vulnerability when processing the mj-include directive within an MJML document.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mjmlnpm | < 4.6.3 | 4.6.3 |
Affected products
3- MJML/MJMLdescription
Patches
Vulnerability mechanics
References
9- github.com/mjmlio/mjml/commit/30e29ed2cdaec8684d60a6d12ea07b611c765a12nvdPatchThird Party AdvisoryWEB
- packetstormsecurity.com/files/158111/MJML-4.6.2-Path-Traversal.htmlnvdExploitThird Party AdvisoryVDB EntryWEB
- seclists.org/fulldisclosure/2020/Jun/23nvdExploitMailing ListThird Party AdvisoryWEB
- github.com/advisories/GHSA-4hch-r9xf-6vfrghsaADVISORY
- github.com/mjmlio/mjml/releases/tag/v4.6.3nvdRelease NotesThird Party AdvisoryWEB
- mjml.io/communitynvdVendor Advisory
- nvd.nist.gov/vuln/detail/CVE-2020-12827ghsaADVISORY
- twitter.com/mjmlionvdThird Party Advisory
- rcesecurity.comnvdBroken Link
News mentions
0No linked articles in our index yet.