{ "id": "CVE-2024-26151", "sourceIdentifier": "security-advisories@github.com", "published": "2024-02-22T19:15:09.300", "lastModified": "2024-02-23T02:42:54.547", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "The `mjml` PyPI package, found at the `FelixSchwarz/mjml-python` GitHub repo, is an unofficial Python port of MJML, a markup language created by Mailjet. All users of `FelixSchwarz/mjml-python` who insert untrusted data into mjml templates unless that data is checked in a very strict manner. User input like `<script>` would be rendered as `