Mammoth.js 1.3.0 至 1.12.3(不含 1.12.3)版本中存在一个正则表达式拒绝服务(ReDoS)漏洞。该漏洞位于 lib/styles/parser/tokeniser.js 文件中的样式映射标记器(style map tokeniser)里,原因是存在重叠的正则表达式替代分支。攻击者可以构造一个包含未终止的、由重复反斜杠转义序列组成的引号内字符串的 .docx 文件,并通过 mammoth/style-map 机制触发该漏洞,从而导致 Node.js 事件循环被阻塞。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| mwilliamson | mammoth.js | 1.3.0< 1.12.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mwilliamson | mammoth.js | 1.3.0 ~ 1.12.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet