mammoth(又名 mammoth.js)在版本 1.12.2 之前存在原型污染漏洞,该漏洞出现在处理文档中定义的样式时。攻击者可以通过构造恶意的 .docx 文件,将任意属性添加到 中。在版本 1.11.0 至 1.12.1 中,如果在同一进程中继续转换其他文档并返回转换后的 HTML,应用程序还可能通过设置 为 ,将本地服务器文件的内容泄露给提供这些文档的一方。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| mwilliamson | mammoth.js | < 1.12.2 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mwilliamson | mammoth.js | 0 ~ 1.12.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet