๐Ÿ” CVE Alert

CVE-2026-97151

UNKNOWN 0.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a document. Converting a crafted .docx file allows an attacker to add arbitrary properties to Object.prototype. In 1.11.0 through 1.12.1, applications that convert further documents in the same process and return the converted HTML can also disclose the contents of local server files (to the party supplying the documents) by setting externalFileAccess to true.

CWE CWE-1321
Vendor mwilliamson
Product mammoth.js
Published Sep 24, 2026
Stay Ahead of the Next One

Get instant alerts for mwilliamson mammoth.js

Be the first to know when new unknown vulnerabilities affecting mwilliamson mammoth.js are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

mwilliamson / mammoth.js
0 < 1.12.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
raw.githubusercontent.com: https://raw.githubusercontent.com/mwilliamson/mammoth.js/master/NEWS npmjs.com: https://www.npmjs.com/package/mammoth github.com: https://github.com/mwilliamson/mammoth.js/commit/31f0c370be4b95ac4fa285fea3be970606735f16 github.com: https://github.com/mwilliamson/mammoth.js/commit/2888fa158d67c1419199f152326e12a05618b53e