XML Parsing Vulnerability in MPXJ Library Affects Project File Handling
CVE-2026-61570
7.5HIGH
What is CVE-2026-61570?
An XML parsing issue has been identified in versions 5.5.5 through 16.4.1 of the MPXJ library. This vulnerability arises from the improper configuration of the DocumentBuilder used in MerlinReader, which retains default settings, including enabled doctype declarations and external entities when parsing XML from the ZTIMEINTERVALS column of Merlin project SQLite databases. As a consequence, there exists the potential for a specially crafted database to prompt the parser to access arbitrary local files. While the way MPXJ processes the parsed XML minimizes the likelihood of disclosing sensitive file contents, users of versions prior to 16.4.1 should upgrade to the latest release to mitigate potential risks.
Affected Version(s)
mpxj >= 5.5.5, < 16.4.1
