Description
mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a document. Converting a crafted .docx file allows an attacker to add arbitrary properties to Object.prototype. In 1.11.0 through 1.12.1, applications that convert further documents in the same process and return the converted HTML can also disclose the contents of local server files (to the party supplying the documents) by setting externalFileAccess to true.
Published: 2026-09-24
Score: 8.4 High
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Upgrade to mammoth 1.12.2 or later.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 24 Sep 2026 05:45:00 +0000

Type Values Removed Values Added
Title Prototype Pollution in mammoth.js via Malicious DOCX

Thu, 24 Sep 2026 03:30:00 +0000

Type Values Removed Values Added
Description mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a document. Converting a crafted .docx file allows an attacker to add arbitrary properties to Object.prototype. In 1.11.0 through 1.12.1, applications that convert further documents in the same process and return the converted HTML can also disclose the contents of local server files (to the party supplying the documents) by setting externalFileAccess to true.
Weaknesses CWE-1321
References
Metrics cvssV4_0

{'score': 8.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-24T03:08:15.523Z

Reserved: 2026-09-24T03:08:15.164Z

Link: CVE-2026-97151

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-24T04:18:06.027

Modified: 2026-09-24T04:18:06.027

Link: CVE-2026-97151

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-24T05:30:05Z

Weaknesses
  • CWE-1321

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')