Back

HIGH

mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a document

Published Sep 24, 2026

Description

mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a document. Converting a crafted .docx file allows an attacker to add arbitrary properties to Object.prototype. In 1.11.0 through 1.12.1, applications that convert further documents in the same process and return the converted HTML can also disclose the contents of local server files (to the party supplying the documents) by setting externalFileAccess to true.

Affected products

Remediation

Vendor solution

Upgrade to mammoth 1.12.2 or later.

Metrics

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 24, 2026
Updated Sep 24, 2026
Reserved Sep 24, 2026
CISA Vulnrichment
Updated Sep 24, 2026
NVD
Status Received
Modified Sep 24, 2026
Red Hat
Severity n/a
Public date n/a