Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to mammoth 1.12.2 or later.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 24 Sep 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Sep 2026 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mwilliamson
Mwilliamson mammoth.js |
|
| Vendors & Products |
Mwilliamson
Mwilliamson mammoth.js |
Thu, 24 Sep 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Prototype Pollution in mammoth.js via Malicious DOCX |
Thu, 24 Sep 2026 03:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a document. Converting a crafted .docx file allows an attacker to add arbitrary properties to Object.prototype. In 1.11.0 through 1.12.1, applications that convert further documents in the same process and return the converted HTML can also disclose the contents of local server files (to the party supplying the documents) by setting externalFileAccess to true. | |
| Weaknesses | CWE-1321 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-09-24T13:02:42.611Z
Reserved: 2026-09-24T03:08:15.164Z
Link: CVE-2026-97151
Updated: 2026-09-24T13:02:35.415Z
Status : Received
Published: 2026-09-24T04:18:06.027
Modified: 2026-09-24T13:17:18.920
Link: CVE-2026-97151
No data.
OpenCVE Enrichment
Updated: 2026-09-24T09:08:51Z
-
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')