MJML allows mj-include directory traversal due to an incomplete fix for CVE-2020-12827
Moderate severity
GitHub Reviewed
Published
Dec 15, 2025
to the GitHub Advisory Database
•
Updated Dec 17, 2025
Give feedback on Dependabot alerts