{"id":"CVE-2026-65829","title":"MPXJ is an open source library to read and write project plans from a variety of file formats and databases","summary":"MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 7.3.0 until 16.5.0, reading a suitably crafted Primavera P3 PRX or SureTrak STX file can cause MPXJ to write files to arbit…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-22"],"vendor":"MPXJ","product":"MPXJ.Net","affected":["MPXJ.Net >= 7.3.0, < 16.5.0","mpxj >= 7.3.0, < 16.5.0","mpxj >= 7.3.0, < 16.5.0","net.sf.mpxj >= 7.3.0, < 16.5.0","net.sf.mpxj-for-csharp >= 7.3.0, < 16.5.0","net.sf.mpxj-for-vb >= 7.3.0, < 16.5.0","net.sf.mpxj:mpxj >= 7.3.0, < 16.5.0"],"patched":["MPXJ.Net 16.5.0","mpxj 16.5.0","mpxj 16.5.0","net.sf.mpxj 16.5.0","net.sf.mpxj-for-csharp 16.5.0","net.sf.mpxj-for-vb 16.5.0","net.sf.mpxj:mpxj 16.5.0"],"published":"2026-09-22","updated":"2026-09-22","sourceUpdated":"2026-09-22T20:17:05.060","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-65829","references":[{"url":"https://github.com/joniles/mpxj/commit/4347315afab1ef5a2907978a754fbc5b0ff58e6f","label":"security-advisories@github.com"},{"url":"https://github.com/joniles/mpxj/releases/tag/v16.5.0","label":"security-advisories@github.com"},{"url":"https://github.com/joniles/mpxj/security/advisories/GHSA-7952-gx68-cjqr","label":"security-advisories@github.com"},{"url":"https://github.com/advisories/GHSA-7952-gx68-cjqr"}],"tags":["nvd","ghsa","nuget","cve.org"],"aliases":["GHSA-7952-gx68-cjqr"],"ecosystem":"nuget","ingestedAt":"2026-09-22T20:10:15.094Z","slug":"CVE-2026-65829","body":"## Overview\n\nMPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 7.3.0 until 16.5.0, reading a suitably crafted Primavera P3 PRX or SureTrak STX file can cause MPXJ to write files to arbitrary locations in the filesystem. This issue is fixed in version 16.5.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-65829)\n\nAffected packages:\n\n- `MPXJ.Net >= 7.3.0, < 16.5.0`\n- `mpxj >= 7.3.0, < 16.5.0`\n- `mpxj >= 7.3.0, < 16.5.0`\n- `net.sf.mpxj >= 7.3.0, < 16.5.0`\n- `net.sf.mpxj-for-csharp >= 7.3.0, < 16.5.0`\n- `net.sf.mpxj-for-vb >= 7.3.0, < 16.5.0`\n- `net.sf.mpxj:mpxj >= 7.3.0, < 16.5.0`\n\nPatched in:\n\n- `MPXJ.Net 16.5.0`\n- `mpxj 16.5.0`\n- `mpxj 16.5.0`\n- `net.sf.mpxj 16.5.0`\n- `net.sf.mpxj-for-csharp 16.5.0`\n- `net.sf.mpxj-for-vb 16.5.0`\n- `net.sf.mpxj:mpxj 16.5.0`\n\nSource: https://github.com/advisories/GHSA-7952-gx68-cjqr","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}