CVE-2026-65829: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in joniles mpxj
MPXJ, an open source library for reading and writing project plans, contains a path traversal vulnerability (CWE-22) in versions from 7.3.0 up to but not including 16.5.0. This flaw allows an attacker to craft Primavera P3 PRX or SureTrak STX files that cause MPXJ to write files to arbitrary filesystem locations. The issue is resolved in version 16.5.0.
AI Analysis
Technical Summary
CVE-2026-65829 describes a path traversal vulnerability in the joniles MPXJ library affecting versions >=7.3.0 and <16.5.0. When processing specially crafted Primavera P3 PRX or SureTrak STX files, MPXJ may write files outside the intended directory, potentially leading to unauthorized file writes. This vulnerability is fixed in version 16.5.0.
Potential Impact
The vulnerability allows an attacker to cause MPXJ to write files to arbitrary locations on the filesystem when processing maliciously crafted project plan files. This can lead to integrity issues by overwriting or creating files in unintended locations. There is no confidentiality or availability impact reported. The CVSS score is 5.3 (medium severity), reflecting limited impact confined to integrity.
Mitigation Recommendations
Upgrade MPXJ to version 16.5.0 or later, where this path traversal vulnerability is fixed. No other mitigation is indicated or required.
CVE-2026-65829: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in joniles mpxj
Description
MPXJ, an open source library for reading and writing project plans, contains a path traversal vulnerability (CWE-22) in versions from 7.3.0 up to but not including 16.5.0. This flaw allows an attacker to craft Primavera P3 PRX or SureTrak STX files that cause MPXJ to write files to arbitrary filesystem locations. The issue is resolved in version 16.5.0.
CVSS v3.1
Score 5.3medium
Affected software
joniles
mpxj
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-65829 describes a path traversal vulnerability in the joniles MPXJ library affecting versions >=7.3.0 and <16.5.0. When processing specially crafted Primavera P3 PRX or SureTrak STX files, MPXJ may write files outside the intended directory, potentially leading to unauthorized file writes. This vulnerability is fixed in version 16.5.0.
Potential Impact
The vulnerability allows an attacker to cause MPXJ to write files to arbitrary locations on the filesystem when processing maliciously crafted project plan files. This can lead to integrity issues by overwriting or creating files in unintended locations. There is no confidentiality or availability impact reported. The CVSS score is 5.3 (medium severity), reflecting limited impact confined to integrity.
Mitigation Recommendations
Upgrade MPXJ to version 16.5.0 or later, where this path traversal vulnerability is fixed. No other mitigation is indicated or required.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-07-22T23:16:47.752Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ab2df31f7a7c54106b20912
Added to database: 09/22/2026, 20:04:01 UTC
Last enriched: 09/22/2026, 20:18:21 UTC
Last updated: 09/22/2026, 20:57:46 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.