CVE-2024-26151 is a medium-severity vulnerability affecting the felixschwarz/mjml-python library versions 0.10.0 through 0.10.x, allowing for cross-site scripting (XSS) due to improper neutralization of untrusted input in MJML templates. An attacker could inject malicious HTML, potentially controlling email content sent to other users. The CVSS score is 5.4 (MEDIUM), indicating a network-based attack with low complexity, requiring user interaction, and resulting in low impact to confidentiality and integrity. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.10.0CPE matchmatch criteria | cpe:2.3:a:felixschwarz:mjml-python:0.10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.