CVE-2024-26151 Vulnerability Details

  /     /     /  

CVE-2024-26151 Metadata Quick Info

CVE Published: 22/02/2024 | CVE Updated: 22/08/2024 | CVE Year: 2024
Source: GitHub_M | Vendor: FelixSchwarz | Product: mjml-python
Status : PUBLISHED

CVE-2024-26151 Description

The `mjml` PyPI package, found at the `FelixSchwarz/mjml-python` GitHub repo, is an unofficial Python port of MJML, a markup language created by Mailjet. All users of `FelixSchwarz/mjml-python` who insert untrusted data into mjml templates unless that data is checked in a very strict manner. User input like `<script>` would be rendered as `