CyberRota Analysis
AI-GeneratedMammoth.js versions prior to 1.12.2 are susceptible to prototype pollution, enabling attackers to inject arbitrary properties into Object.prototype through crafted .docx files. Additionally, versions 1.11.0 to 1.12.1 can inadvertently expose local server file contents if externalFileAccess is set to true during document conversion. Organizations utilizing Mammoth.js for document processing should prioritize updating to the latest version to mitigate these vulnerabilities.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype pollution when reading the styles defined in a document. Converting a crafted .docx file allows an attacker to add arbitrary properties to Object.prototype. In 1.11.0 through 1.12.1, applications that convert further documents in the same process and return the converted HTML can also disclose the contents of local server files (to the party supplying the documents) by setting externalFileAccess to true.