StackRadar

CVE-2025-67898

Medium

Advisory

Published 15 Dec 2025In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
4.5
base score, highest
EPSS
0.003
18th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
18
of 17,781 indexed, latest versions
Container images
15
deployed by those charts
Fix available
1 of 1
affected package

MJML allows mj-include directory traversal due to an incomplete fix for CVE-2020-12827

Carried by container images the latest versions of 18 of 17,781 indexed charts deploy, on 15 images.

Affected packageAffected versionsFixed inImages
mjmlnpm4.12.0, 4.13.0, 4.14.1, 5.0.0-alpha.45.0.0-alpha.915
OSV records
GHSA-45h5-66jx-r2wf

Charts affected

18 by stars
ChartLatestAffected imagesRadar Score
hoppscotchdeliveryheroVerified publisher0.3.21 of 1See more

hoppscotch deliveryhero 0.3.2

1 of the 1 container images this version deploys carry CVE-2025-67898.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
mjml@5.0.0-alpha.4
5.0.0-alpha.9

Open the chart page →

3,451
graphql-hivegraphql-hive1.0.01 of 17See more

graphql-hive graphql-hive 1.0.0

1 of the 17 container images this version deploys carry CVE-2025-67898.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
mjml@4.13.0
5.0.0-alpha.9

Open the chart page →

10,311
data-fairdata354-helmVerified publisher1.1.21 of 12See more

data-fair data354-helm 1.1.2

1 of the 12 container images this version deploys carry CVE-2025-67898.

Container imageDigestPackageFixed in
ghcr.io/data-fair/simple-directory:438a4f32fad82
mjml@4.12.0
5.0.0-alpha.9

Open the chart page →

38,346
speckle-serverspeckleVerified publisher2.26.31 of 4See more

speckle-server speckle 2.26.3

1 of the 4 container images this version deploys carry CVE-2025-67898.

Container imageDigestPackageFixed in
speckle/speckle-server:2.26.379f14a2bf931
mjml@4.14.1
5.0.0-alpha.9

Open the chart page →

10,380
hive-appgraphql-hive1.0.01 of 1See more

hive-app graphql-hive 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-67898.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
mjml@4.13.0
5.0.0-alpha.9

Open the chart page →

2,682
hive-appgraphql-hive-subcharts1.0.01 of 1See more

hive-app graphql-hive-subcharts 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-67898.

Container imageDigestPackageFixed in
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
mjml@4.13.0
5.0.0-alpha.9

Open the chart page →

2,682
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2025-67898.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
mjml@5.0.0-alpha.4
5.0.0-alpha.9

Open the chart page →

3,451
hoppscotchhoppscotch0.1.11 of 1See more

hoppscotch hoppscotch 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-67898.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
mjml@5.0.0-alpha.4
5.0.0-alpha.9

Open the chart page →

3,614
ohmyformkrzwiatrzyk0.0.11 of 1See more

ohmyform krzwiatrzyk 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-67898.

Container imageDigestPackageFixed in
ohmyform/ohmyform:1.0.3afe53f4acdb1
mjml@4.12.0
5.0.0-alpha.9

Open the chart page →

4,230
speckle-server-branch-hotfix-2.19.1speckleVerified publisher2.19.2-branch.hotfix-2.19.1.124125-665e7e11 of 5See more

speckle-server-branch-hotfix-2.19.1 speckle 2.19.2-branch.hotfix-2.19.1.124125-665e7e1

1 of the 5 container images this version deploys carry CVE-2025-67898.

Container imageDigestPackageFixed in
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
mjml@4.14.1
5.0.0-alpha.9

Open the chart page →

16,368
speckle-server-branch-hotfix-2.20.2speckleVerified publisher2.20.3-branch.hotfix-2.20.2.149555-37ea0cb1 of 5See more

speckle-server-branch-hotfix-2.20.2 speckle 2.20.3-branch.hotfix-2.20.2.149555-37ea0cb

1 of the 5 container images this version deploys carry CVE-2025-67898.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
mjml@4.13.0
5.0.0-alpha.9

Open the chart page →

16,400
speckle-server-branch-testingspeckleVerified publisher2.17.14-branch.testing.72707.921a5f81 of 5See more

speckle-server-branch-testing speckle 2.17.14-branch.testing.72707.921a5f8

1 of the 5 container images this version deploys carry CVE-2025-67898.

Container imageDigestPackageFixed in
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
mjml@4.14.1
5.0.0-alpha.9

Open the chart page →

14,679
speckle-server-branch-testing1speckleVerified publisher2.20.6-branch.testing1.154030-9b091141 of 5See more

speckle-server-branch-testing1 speckle 2.20.6-branch.testing1.154030-9b09114

1 of the 5 container images this version deploys carry CVE-2025-67898.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
mjml@4.14.1
5.0.0-alpha.9

Open the chart page →

16,400
speckle-server-branch-testing2speckleVerified publisher2.18.11-branch.testing2.88634-335d4691 of 5See more

speckle-server-branch-testing2 speckle 2.18.11-branch.testing2.88634-335d469

1 of the 5 container images this version deploys carry CVE-2025-67898.

Container imageDigestPackageFixed in
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
mjml@4.13.0
5.0.0-alpha.9

Open the chart page →

14,221
speckle-server-branch-testing3speckleVerified publisher2.18.12-branch.testing3.88744-f55b3411 of 5See more

speckle-server-branch-testing3 speckle 2.18.12-branch.testing3.88744-f55b341

1 of the 5 container images this version deploys carry CVE-2025-67898.

Container imageDigestPackageFixed in
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
mjml@4.14.1
5.0.0-alpha.9

Open the chart page →

14,221
speckle-server-branch-testing4speckleVerified publisher2.20.2-branch.testing4.134160-9fad4b21 of 5See more

speckle-server-branch-testing4 speckle 2.20.2-branch.testing4.134160-9fad4b2

1 of the 5 container images this version deploys carry CVE-2025-67898.

Container imageDigestPackageFixed in
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
mjml@4.13.0
5.0.0-alpha.9

Open the chart page →

16,019
speckle-server-branch-testing5speckleVerified publisher2.21.3-branch.testing5.219631-2153bef1 of 5See more

speckle-server-branch-testing5 speckle 2.21.3-branch.testing5.219631-2153bef

1 of the 5 container images this version deploys carry CVE-2025-67898.

Container imageDigestPackageFixed in
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
mjml@4.13.0
5.0.0-alpha.9

Open the chart page →

15,635
speckle-server-branch-testing6speckleVerified publisher2.25.10-branch.testing6.645-b125c1e1 of 4See more

speckle-server-branch-testing6 speckle 2.25.10-branch.testing6.645-b125c1e

1 of the 4 container images this version deploys carry CVE-2025-67898.

Container imageDigestPackageFixed in
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
mjml@4.13.0
5.0.0-alpha.9

Open the chart page →

11,100

Container images carrying it

15 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
ghcr.io/kamilkisiela/graphql-hive/app:59b64c36c866b3555c135c70de76a884e63f8619a4a3639899f7
mjml@4.13.0
5.0.0-alpha.9
3
hoppscotch/hoppscotch:2024.8.2f1da831950b7
mjml@5.0.0-alpha.4
5.0.0-alpha.9
2
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
mjml@5.0.0-alpha.4
5.0.0-alpha.9
1
ohmyform/ohmyform:1.0.3afe53f4acdb1
mjml@4.12.0
5.0.0-alpha.9
1
speckle/speckle-server:2.17.14-branch.testing.72707.921a5f849d10dcdfb91
mjml@4.14.1
5.0.0-alpha.9
1
speckle/speckle-server:2.19.2-branch.hotfix-2.19.1.124125-665e7e14b6a0750d5aa
mjml@4.14.1
5.0.0-alpha.9
1
speckle/speckle-server:2.20.3-branch.hotfix-2.20.2.149555-37ea0cb52f8eabf5cea
mjml@4.13.0
5.0.0-alpha.9
1
speckle/speckle-server:2.20.2-branch.testing4.134160-9fad4b2687f43ab16f3
mjml@4.13.0
5.0.0-alpha.9
1
speckle/speckle-server:2.25.10-branch.testing6.645-b125c1e75cdf256067b
mjml@4.13.0
5.0.0-alpha.9
1
speckle/speckle-server:2.26.379f14a2bf931
mjml@4.14.1
5.0.0-alpha.9
1
speckle/speckle-server:2.18.12-branch.testing3.88744-f55b34189a5872375f9
mjml@4.14.1
5.0.0-alpha.9
1
speckle/speckle-server:2.21.3-branch.testing5.219631-2153bef8fd157733393
mjml@4.13.0
5.0.0-alpha.9
1
speckle/speckle-server:2.18.11-branch.testing2.88634-335d469bf6a501b2210
mjml@4.13.0
5.0.0-alpha.9
1
speckle/speckle-server:2.20.6-branch.testing1.154030-9b09114e8413f57b327
mjml@4.14.1
5.0.0-alpha.9
1
ghcr.io/data-fair/simple-directory:438a4f32fad82
mjml@4.12.0
5.0.0-alpha.9
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.