CVE-2025-11849Critical· 9.3▾ MidnightMammoth is vulnerable to Directory Traversal
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 51.2 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.9%
0.9% → 1.0%
Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth before 1.11.0; versions of the package org.zwobble.mammoth:mammoth before 1.11.0 are vulnerable to Directory Traversal due to the lack of path or file type validation when processing a docx file containing an image with an external link (r:link attribute instead of embedded r:embed). The library resolves the URI to a file path and after reading, the content is encoded as base64 and included in the HTML output as a data URI. An attacker can read arbitrary files on the system where the conversion is performed or cause an excessive resources consumption by crafting a docx file that links to special device files such as /dev/random or /dev/zero.
mammoth >= 0.3.25, < 1.11.0org.zwobble.mammoth:mammoth < 1.11.0mammoth >= 0.3.25, < 1.11.0Mammoth < 1.11.0Upgrade to a patched release:
mammoth 1.11.0org.zwobble.mammoth:mammoth 1.11.0mammoth 1.11.0Mammoth 1.11.0