216.73.217.22

CVE-2025-11849

· Published 17/10/2025 05:15 · Modified 17/10/2025 15:15

Labels: CVE-2025-11849 2025-10-17CVE-2025-11849CWE-22[email protected]

Essential information

Published
17/10/2025 05:15
Modified
17/10/2025 15:15
Author
Creator
CVSS
6.4 MEDIUM (v3) 6.4 MEDIUM (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth before 1.11.0; versions of the package org.zwobble.mammoth:mammoth before 1.11.0 are vulnerable to Directory Traversal due to the lack of path or file type validation when processing a docx file containing an image with an external link (r:link attribute instead of embedded r:embed). The library resolves the URI to a file path and after reading, the content is encoded as base64 and included in the HTML output as a data URI. An attacker can read arbitrary files on the system where the conversion is performed or cause an excessive resources consumption by crafting a docx file that links to special device files such as /dev/random or /dev/zero.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
org.zwobble / mammoth cpe:2.3:a:org.zwobble:mammoth:<1.11.0:*:*:*:*:*:*:*

References