{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/mpxj/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:mpxj:mpxj:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-61570"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["mpxj (\u003e= 5.5.5, \u003c 16.4.1)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","xxe","java",".net","python","ruby"],"_cs_type":"advisory","_cs_vendors":["MPXJ"],"content_html":"\u003cp\u003eThe MPXJ project library contains an XML External Entity (XXE) injection vulnerability (CVE-2026-61570) within its MerlinReader component. The issue originates from the use of default DocumentBuilder configurations that do not disable Document Type Definition (DTD) processing when parsing XML content stored in the ZTIMEINTERVALS column of Merlin project SQLite files.\u003c/p\u003e\n\u003cp\u003eAn attacker can supply a malicious Merlin project file containing a crafted XML payload to trigger the vulnerability. While the current processing logic within MPXJ limits the ability to exfiltrate the contents of the read files, the vulnerability exposes local system files to unauthorized access. This issue affects multiple language ports including Maven, RubyGems, NuGet, and Python/pip packages for MPXJ versions 5.5.5 through 16.4.0. Users are advised to upgrade to MPXJ 16.4.1 or later to resolve this vulnerability.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows an attacker to perform arbitrary file reads on the system where the MPXJ library parses untrusted Merlin project files. While successful exploitation is hindered by subsequent application logic preventing direct exfiltration of the data, it represents a high-severity security risk for any software component or enterprise application utilizing MPXJ to process external Merlin project files.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of MPXJ to version 16.4.1 or later to remediate CVE-2026-61570.\u003c/li\u003e\n\u003cli\u003eImplement strict validation of Merlin project files before ingestion into any application utilizing the MPXJ library.\u003c/li\u003e\n\u003cli\u003eIf upgrading is not immediately possible, implement pre-processing steps to strip doctype declarations from the ZTIMEINTERVALS column of Merlin SQLite databases prior to passing them to the reader.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-23T07:55:23Z","date_published":"2026-09-23T07:55:23Z","id":"https://feed.craftedsignal.io/briefs/2026-09-mpxj-xxe/","summary":"MPXJ is vulnerable to an XML External Entity (XXE) injection flaw via the MerlinReader component when processing XML content within the ZTIMEINTERVALS column of Merlin project SQLite files, allowing for arbitrary file reads.","title":"XXE Vulnerability in MPXJ MerlinReader","url":"https://feed.craftedsignal.io/briefs/2026-09-mpxj-xxe/"}],"language":"en","title":"CraftedSignal Threat Feed - MPXJ","version":"https://jsonfeed.org/version/1.1"}