MEDIUM 5.3 NVD
CVE-2026-65829
MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 7.3.0 until 16.5.0, reading a suitably crafted
MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 7.3.0 until 16.5.0, reading a suitably crafted Primavera P3 PRX or SureTrak STX file can cause MPXJ to write files to arbitrary locations in the filesystem. This issue is fixed in version 16.5.0.
References
- https://github.com/joniles/mpxj/commit/4347315afab1ef5a2907978a754fbc5b0ff58e6f
- https://github.com/joniles/mpxj/releases/tag/v16.5.0
- https://github.com/joniles/mpxj/security/advisories/GHSA-7952-gx68-cjqr
This medium severity vulnerability with a CVSS score of 5.3 was published on 2026-09-22 via NVD.
vulnfeed aggregates 13417 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.