CVE-2025-70296

A stored HTML injection vulnerability in the Recipe Notes rendering component in Mealie 3.3.1 allows remote authenticated users to inject arbitrary HTML, resulting in user interface redressing within the recipe view.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mealie:mealie:*:*:*:*:*:*:*:*

History

23 Feb 2026, 15:34

Type Values Removed Values Added
CPE cpe:2.3:a:mealie:mealie:*:*:*:*:*:*:*:*
First Time Mealie
Mealie mealie
Summary
  • (es) Una vulnerabilidad de inyección HTML almacenada en el componente de renderizado de Notas de Receta en Mealie 3.3.1 permite a usuarios autenticados remotos inyectar HTML arbitrario, resultando en un rediseño de la interfaz de usuario dentro de la vista de la receta.
References () https://github.com/chrisWalker11/Cves/blob/main/CVE-2025-70296/CVE-2025-70296.md - () https://github.com/chrisWalker11/Cves/blob/main/CVE-2025-70296/CVE-2025-70296.md - Exploit, Third Party Advisory
References () https://github.com/mealie-recipes/mealie/issues/6690 - () https://github.com/mealie-recipes/mealie/issues/6690 - Issue Tracking
References () https://github.com/mealie-recipes/mealie/pull/6743 - () https://github.com/mealie-recipes/mealie/pull/6743 - Issue Tracking

12 Feb 2026, 21:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
CWE CWE-77

11 Feb 2026, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-11 19:15

Updated : 2026-02-23 15:34


NVD link : CVE-2025-70296

Mitre link : CVE-2025-70296

CVE.ORG link : CVE-2025-70296


JSON object : View

Products Affected

mealie

  • mealie
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')