Advisory Database
  • Advisories
  • Dependency Scanning
  1. pypi
  2. ›
  3. mpxj
  4. ›
  5. CVE-2026-61570

CVE-2026-61570: MPXJ: XXE Vulnerability in MerlinReader

September 22, 2026

MPXJ used the default configuration when creating a DocumentBuilder instance, which leaves doctype declarations enabled, when parsing the XML content of the ZTIMEINTERVALS column from a Merlin project SQLite file. This would allow a carefully crafted XML payload to read an arbitrary file. However, although an arbitrary file can be read, the way the resulting parsed XML is processed by MPXJ means that the data it contains is unlikely to be available for exfiltration.

References

  • github.com/advisories/GHSA-5vvx-3h34-f3gj
  • github.com/joniles/mpxj/commit/6e8288bc4d1cd62842af298004dc74fe66fb0805
  • github.com/joniles/mpxj/releases/tag/v16.4.1
  • github.com/joniles/mpxj/security/advisories/GHSA-5vvx-3h34-f3gj
  • nvd.nist.gov/vuln/detail/CVE-2026-61570

Code Behaviors & Features

Detect and mitigate CVE-2026-61570 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 5.5.5 before 16.4.1

Fixed versions

  • 16.4.1

Solution

Upgrade to version 16.4.1 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-611: Improper Restriction of XML External Entity Reference

Source file

pypi/mpxj/CVE-2026-61570.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 23 Sep 2026 00:16:35 +0000.