rubygems package report

Is mpxj safe?

2 known vulnerabilities, worst severity HIGH.

// reach

0 direct dependencies

none carry a known advisory

    0 packages depend on it

    an advisory here reaches each of them

      Create a free accountfor every dependency path, dependent and what to upgrade
      // ai model usage

      Tracked for PyPI packages. HuggingFace models declare Python dependencies, so rubygems packages are not covered.


      cvss
      0.0
      high

      severity out of 10

      epss
      0.00%
      low

      chance of exploitation in 30 days, 26th percentile of all CVEs

      xyz score
      0.0
      low

      CyberXYZ composite out of 10

      fig. 01 — GHSA-5vvx-3h34-f3gj, the advisory selected below

      // 2 advisories

      GHSA-5vvx-3h34-f3gj

      HIGHCVE-2026-61570
      // impact

      MPXJ used the default configuration when creating a DocumentBuilder instance, which leaves doctype declarations enabled, when parsing the XML content of the ZTIMEINTERVALS column from a Merlin project SQLite file. This would allow a carefully crafted XML payload to read an arbitrary file. However, although an arbitrary file can be read, the way the resulting parsed XML is processed by MPXJ means that the data it contains is unlikely to be available for exfiltration.

      // patches

      The patch is included in MPXJ 16.4.1

      // workarounds

      Potential workarounds include:

      • Avoid reading Merlin project files with MPXJ
      • Only accept Merlin project files from trusted sources
      • Preprocess Merlin SQLite databases to strip doctype declarations from the ZTIMEINTERVALS column
      // cvss v3.1 vector

      CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

      Attack vector
      Network
      Attack complexity
      Low
      Privileges required
      None
      User interaction
      None
      Scope
      Unchanged
      Confidentiality
      High
      Integrity
      None
      Availability
      None

      Checked 2026-10-02 at 15:06 UTC. The most recent advisory here was published 2026-09-22. Updated continuously from NVD, GHSA, OSV and CNA feeds.

      Think a verdict here is wrong? Tell us — we respond within 2 business days.