{"id":"CVE-2025-11849","aliases":["GHSA-rmjr-87wv-gf87","PYSEC-2026-1603"],"url":"https://o3.security/vulnerability/CVE-2025-11849","summary":"Mammoth is vulnerable to Directory Traversal","details":"Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth before 1.11.0; versions of the package org.zwobble.mammoth:mammoth before 1.11.0 are vulnerable to Directory Traversal due to the lack of path or file type validation when processing a docx file containing an image with an external link (r:link attribute instead of embedded r:embed). The library resolves the URI to a file path and after reading, the content is encoded as base64 and included in the HTML output as a data URI. An attacker can read arbitrary files on the system where the conversion is performed or cause an excessive resources consumption by crafting a docx file that links to special device files such as /dev/random or /dev/zero.","published":"2025-10-17T05:00:06.278Z","modified":"2026-08-12T03:51:37.490440776Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.zwobble.mammoth:mammoth","fixedVersion":"1.11.0"},{"ecosystem":"npm","name":"mammoth","fixedVersion":"1.11.0"},{"ecosystem":"NuGet","name":"Mammoth","fixedVersion":"1.11.0"},{"ecosystem":"PyPI","name":"mammoth","fixedVersion":"1.11.0"}],"fix":{"url":"https://github.com/mwilliamson/mammoth.js/commit/c54aaeb43a7941317c1f3c119ffa92090f988820","label":"mwilliamson/mammoth.js@c54aaeb"},"references":[{"type":"WEB","url":"https://gist.github.com/AudunWA/4d690d9ae5efdafe7cf71d9c2ee90a10"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-DOTNET-MAMMOTH-13561968"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JAVA-ORGZWOBBLEMAMMOTH-13561969"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-MAMMOTH-13554470"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-PYTHON-MAMMOTH-13561967"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/11xxx/CVE-2025-11849.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-11849"},{"type":"FIX","url":"https://github.com/mwilliamson/mammoth.js/commit/c54aaeb43a7941317c1f3c119ffa92090f988820"},{"type":"PACKAGE","url":"https://github.com/mwilliamson/java-mammoth"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:37.490440776Z"}}