MJML prior to 4.6.3 contains a path traversal vulnerability when processing the mj-include directive within an MJML document.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:mjml:mjml:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"fixed": "4.6.3"
}
],
"source": "CPE_RANGE",
"vendor_product": "mjml:mjml"
}
]
}