CVE-2026-97151
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a document. Converting a crafted .docx file allows an attacker to add arbitrary properties to Object.prototype. In 1.11.0 through 1.12.1, applications that convert further documents in the same process and return the converted HTML can also disclose the contents of local server files (to the party supplying the documents) by setting externalFileAccess to true.
| CWE | CWE-1321 |
| Vendor | mwilliamson |
| Product | mammoth.js |
| Published | Sep 24, 2026 |
Stay Ahead of the Next One
Get instant alerts for mwilliamson mammoth.js
Be the first to know when new unknown vulnerabilities affecting mwilliamson mammoth.js are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
mwilliamson / mammoth.js
0 < 1.12.2
References
raw.githubusercontent.com: https://raw.githubusercontent.com/mwilliamson/mammoth.js/master/NEWS npmjs.com: https://www.npmjs.com/package/mammoth github.com: https://github.com/mwilliamson/mammoth.js/commit/31f0c370be4b95ac4fa285fea3be970606735f16 github.com: https://github.com/mwilliamson/mammoth.js/commit/2888fa158d67c1419199f152326e12a05618b53e