Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-7952-gx68-cjqr | MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers |
Wed, 23 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Sep 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Joniles
Joniles mpxj |
|
| Vendors & Products |
Joniles
Joniles mpxj |
Tue, 22 Sep 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MPXJ is an open source library to read and write project plans from a variety of file formats and databases. From 7.3.0 until 16.5.0, reading a suitably crafted Primavera P3 PRX or SureTrak STX file can cause MPXJ to write files to arbitrary locations in the filesystem. This issue is fixed in version 16.5.0. | |
| Title | MPXJ: Potential Path Traversal Vulnerability in Primavera P3 PRX and SureTrak STX readers | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-23T12:41:05.423Z
Reserved: 2026-07-22T23:16:47.752Z
Link: CVE-2026-65829
Updated: 2026-09-23T12:40:53.381Z
Status : Received
Published: 2026-09-22T20:17:05.060
Modified: 2026-09-23T13:17:27.927
Link: CVE-2026-65829
No data.
OpenCVE Enrichment
Updated: 2026-09-23T09:11:50Z
-
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Github GHSA