PT-2026-97698 · Npm · Mammoth
CVE-2026-97151
·
Published
2026-09-24
·
Updated
2026-09-24
CVSS v4.0
8.4
High
| Vector | AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
mammoth versions prior to 1.12.2
Description
The software is susceptible to prototype pollution when reading styles defined in a document. An attacker can add arbitrary properties to
Object.prototype by converting a specially crafted .docx file. In versions 1.11.0 through 1.12.1, if an application converts additional documents within the same process and returns the resulting HTML, it may lead to the disclosure of local server files by setting the externalFileAccess variable to true.Recommendations
Update to version 1.12.2 or later.
Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mammoth