OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-97151

HIGH · CVSS 8.4 EPSS 0.36% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-24 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Mammoth.js versions prior to 1.12.2 are susceptible to prototype pollution, enabling attackers to inject arbitrary properties into Object.prototype through crafted .docx files. Additionally, versions 1.11.0 to 1.12.1 can inadvertently expose local server file contents if externalFileAccess is set to true during document conversion. Organizations utilizing Mammoth.js for document processing should prioritize updating to the latest version to mitigate these vulnerabilities.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-97151
Severity
HIGH
CVSS
8.4
EPSS
0.36%

Original NVD Description

mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a document. Converting a crafted .docx file allows an attacker to add arbitrary properties to Object.prototype. In 1.11.0 through 1.12.1, applications that convert further documents in the same process and return the converted HTML can also disclose the contents of local server files (to the party supplying the documents) by setting externalFileAccess to true.