diff --git a/advisories/github-reviewed/2024/02/GHSA-578p-fxmm-6229/GHSA-578p-fxmm-6229.json b/advisories/github-reviewed/2024/02/GHSA-578p-fxmm-6229/GHSA-578p-fxmm-6229.json new file mode 100644 index 00000000000..e56a5595312 --- /dev/null +++ b/advisories/github-reviewed/2024/02/GHSA-578p-fxmm-6229/GHSA-578p-fxmm-6229.json @@ -0,0 +1,81 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-578p-fxmm-6229", + "modified": "2024-02-22T21:40:59Z", + "published": "2024-02-22T21:40:59Z", + "aliases": [ + "CVE-2024-26151" + ], + "summary": "Potentially untrusted input is rendered as HTML in final output", + "details": "### Impact\n\nAll users of mjml-python who insert untrusted data into mjml templates unless that data is checked in a very strict manner. User input like `<script>` would be rendered as `