CVE-2025-70296

MEDIUM

Mealie 3.3.1 - XSS

Title source: llm
STIX 2.1

Description

A stored HTML injection vulnerability in the Recipe Notes rendering component in Mealie 3.3.1 allows remote authenticated users to inject arbitrary HTML, resulting in user interface redressing within the recipe view.

Scores

CVSS v3 5.4
EPSS 0.0005
EPSS Percentile 16.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-77
Status published
Products (1)
mealie/mealie 3.3.1 - 3.8.0
Published Feb 11, 2026
Tracked Since Feb 18, 2026