CVE-2025-70296

A stored HTML injection vulnerability in the Recipe Notes rendering component in Mealie 3.3.1 allows remote authenticated users to inject arbitrary HTML, resulting in user interface redressing within the recipe view.
Configurations

Configuration 1 (hide)

cpe:2.3:a:mealie:mealie:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-02-11 19:15

Updated : 2026-02-23 15:34


NVD link : CVE-2025-70296

Mitre link : CVE-2025-70296

CVE.ORG link : CVE-2025-70296


JSON object : View

Products Affected

mealie

  • mealie
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')