XML Parsing Vulnerability in MPXJ Library Affects Project File Handling
CVE-2026-61570

7.5HIGH

Key Information:

Vendor

Joniles

Status
Vendor
CVE Published:
22 September 2026

What is CVE-2026-61570?

An XML parsing issue has been identified in versions 5.5.5 through 16.4.1 of the MPXJ library. This vulnerability arises from the improper configuration of the DocumentBuilder used in MerlinReader, which retains default settings, including enabled doctype declarations and external entities when parsing XML from the ZTIMEINTERVALS column of Merlin project SQLite databases. As a consequence, there exists the potential for a specially crafted database to prompt the parser to access arbitrary local files. While the way MPXJ processes the parsed XML minimizes the likelihood of disclosing sensitive file contents, users of versions prior to 16.4.1 should upgrade to the latest release to mitigate potential risks.

Affected Version(s)

mpxj >= 5.5.5, < 16.4.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.