A stored HTML injection vulnerability in the Recipe Notes rendering component in Mealie 3.3.1 allows remote authenticated users to inject arbitrary HTML, resulting in user interface redressing within the recipe view.
References
| Link | Resource |
|---|---|
| https://github.com/chrisWalker11/Cves/blob/main/CVE-2025-70296/CVE-2025-70296.md | Exploit Third Party Advisory |
| https://github.com/mealie-recipes/mealie/issues/6690 | Issue Tracking |
| https://github.com/mealie-recipes/mealie/pull/6743 | Issue Tracking |
Configurations
History
23 Feb 2026, 15:34
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:mealie:mealie:*:*:*:*:*:*:*:* | |
| First Time |
Mealie
Mealie mealie |
|
| Summary |
|
|
| References | () https://github.com/chrisWalker11/Cves/blob/main/CVE-2025-70296/CVE-2025-70296.md - Exploit, Third Party Advisory | |
| References | () https://github.com/mealie-recipes/mealie/issues/6690 - Issue Tracking | |
| References | () https://github.com/mealie-recipes/mealie/pull/6743 - Issue Tracking |
12 Feb 2026, 21:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
| CWE | CWE-77 |
11 Feb 2026, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-11 19:15
Updated : 2026-02-23 15:34
NVD link : CVE-2025-70296
Mitre link : CVE-2025-70296
CVE.ORG link : CVE-2025-70296
JSON object : View
Products Affected
mealie
- mealie
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')
