PT-2026-97698 · Npm · Mammoth

CVE-2026-97151

·

Published

2026-09-24

·

Updated

2026-09-24

CVSS v4.0

8.4

High

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions mammoth versions prior to 1.12.2
Description The software is susceptible to prototype pollution when reading styles defined in a document. An attacker can add arbitrary properties to Object.prototype by converting a specially crafted .docx file. In versions 1.11.0 through 1.12.1, if an application converts additional documents within the same process and returns the resulting HTML, it may lead to the disclosure of local server files by setting the externalFileAccess variable to true.
Recommendations Update to version 1.12.2 or later.

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97151

Affected Products

Mammoth