mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a document. Converting a crafted .docx file allows an attacker to add arbitrary properties to Object.prototype. In 1.11.0 through 1.12.1, applications that convert further documents in the same process and return the converted HTML can also disclose the contents of local server files (to the party supplying the documents) by setting externalFileAccess to true.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Upgrade to mammoth 1.12.2 or later.
Workaround
No workaround given by the vendor.
References
History
Thu, 24 Sep 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mwilliamson
Mwilliamson mammoth.js |
|
| Vendors & Products |
Mwilliamson
Mwilliamson mammoth.js |
Thu, 24 Sep 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Prototype Pollution in mammoth.js via Malicious DOCX |
Thu, 24 Sep 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a document. Converting a crafted .docx file allows an attacker to add arbitrary properties to Object.prototype. In 1.11.0 through 1.12.1, applications that convert further documents in the same process and return the converted HTML can also disclose the contents of local server files (to the party supplying the documents) by setting externalFileAccess to true. | |
| Weaknesses | CWE-1321 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-24T03:08:15.523Z
Reserved: 2026-09-24T03:08:15.164Z
Link: CVE-2026-97151
No data.
Status : Received
Published: 2026-09-24T04:18:06.027
Modified: 2026-09-24T04:18:06.027
Link: CVE-2026-97151
No data.
OpenCVE Enrichment
Updated: 2026-09-24T09:08:51Z
Weaknesses