CVE-2025-70297

Source
https://cve.org/CVERecord?id=CVE-2025-70297
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-70297.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-70297
Published
2026-02-11T00:00:00Z
Modified
2026-08-12T03:51:14.664521218Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A stored cross-site scripting (XSS) vulnerability in the recipe asset upload and media serving component in Mealie 3.3.1 allows remote authenticated users to inject arbitrary web script or HTML via an uploaded SVG file that is served as image/svg+xml and rendered by a victim s browser.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/70xxx/CVE-2025-70297.json",
    "cna_assigner": "mitre"
}
References

Affected packages

Git / github.com/mealie-recipes/mealie

Affected ranges

Type
GIT
Repo
https://github.com/mealie-recipes/mealie
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "3.3.1"
        },
        {
            "fixed": "3.6.0"
        }
    ],
    "cpe": "cpe:2.3:a:mealie:mealie:*:*:*:*:*:*:*:*",
    "source": "CPE_RANGE"
}

Affected versions

v3.*
v3.3.1
v3.3.2
v3.4.0
v3.5.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-70297.json"