VYPR
Unrated severityNVD Advisory· Published Feb 11, 2026· Updated Feb 12, 2026

CVE-2025-70296

CVE-2025-70296

Description

A stored HTML injection vulnerability in the Recipe Notes rendering component in Mealie 3.3.1 allows remote authenticated users to inject arbitrary HTML, resulting in user interface redressing within the recipe view.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Mealie/Mealiecpe-rescue2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: = 3.3.1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.