CVE-2025-70296

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
11/02/2026
Last modified:
12/02/2026

Description

A stored HTML injection vulnerability in the Recipe Notes rendering component in Mealie 3.3.1 allows remote authenticated users to inject arbitrary HTML, resulting in user interface redressing within the recipe view.