CVE-2022-50897
mPDF 7.0 contains a local file inclusion vulnerability that allows attackers to read arbitrary system files by manipulating annotation file parameters. Attackers can generate URL-encoded or base64 payloads to include local files through crafted annotation content with file path specifications.
- Affected products
- Mpdf
- Mpdf Project Mpdf
- = 7.0.0
- CVSS 4.0
- 8.7 HIGH
- CVSS 3.1
- 5.5 MEDIUM
- EPSS
- 0.5% (38th percentile)
- Weakness
- CWE-98
- NVD status
- Modified
- Published
- 2026-01-13
CVE-2022-50897 at NVD
No indexed exploits for CVE-2022-50897 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2022-50897 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.