Mammoth
Convert Word documents from docx to simple HTML
Activity
- Latest release
- 1mo ago
- Total releases
- 10
- Cadence
- ~11 months
- Last 12 months
- 1
Reach
- Stars
- —
Details
- License
- BSD-2-Clause
- First release
- May 07, 2015
| Version | Released | |
|---|---|---|
1.12.1
minor
| ||
1.11.0
minor
| ||
1.8.0
minor
1 CVE
CVE-2025-11849
GHSA-rmjr-87wv-gf87
PYSEC-2026-1603
Oct 17, 2025
Mammoth is vulnerable to Directory Traversal
Medium
Network
Low
None
Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth before 1.11.0; versions of the package org.zwobble.mammoth:mammoth before 1.11.0 are vulnerable to Directory Traversal due to the lack of path or file type validation when processing a docx file containing an image with an external link (r:link attribute instead of embedded r:embed). The library resolves the URI to a file path and after reading, the content is encoded as base64 and included in the HTML output as a data URI. An attacker can read arbitrary files on the system where the conversion is performed or cause an excessive resources consumption by crafting a docx file that links to special device files such as /dev/random or /dev/zero. Affected versions
0.0.1
0.0.2
1.3.1
1.3.2
1.4.0
1.8.0
Fixed in
1.11.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.7.0-alpha.3
pre
1 CVE
CVE-2025-11849
GHSA-rmjr-87wv-gf87
PYSEC-2026-1603
Oct 17, 2025
Mammoth is vulnerable to Directory Traversal
Medium
Network
Low
None
Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth before 1.11.0; versions of the package org.zwobble.mammoth:mammoth before 1.11.0 are vulnerable to Directory Traversal due to the lack of path or file type validation when processing a docx file containing an image with an external link (r:link attribute instead of embedded r:embed). The library resolves the URI to a file path and after reading, the content is encoded as base64 and included in the HTML output as a data URI. An attacker can read arbitrary files on the system where the conversion is performed or cause an excessive resources consumption by crafting a docx file that links to special device files such as /dev/random or /dev/zero. Affected versions
0.0.1
0.0.2
1.3.1
1.3.2
1.4.0
1.8.0
Fixed in
1.11.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.7.0-alpha.2
pre
1 CVE
CVE-2025-11849
GHSA-rmjr-87wv-gf87
PYSEC-2026-1603
Oct 17, 2025
Mammoth is vulnerable to Directory Traversal
Medium
Network
Low
None
Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth before 1.11.0; versions of the package org.zwobble.mammoth:mammoth before 1.11.0 are vulnerable to Directory Traversal due to the lack of path or file type validation when processing a docx file containing an image with an external link (r:link attribute instead of embedded r:embed). The library resolves the URI to a file path and after reading, the content is encoded as base64 and included in the HTML output as a data URI. An attacker can read arbitrary files on the system where the conversion is performed or cause an excessive resources consumption by crafting a docx file that links to special device files such as /dev/random or /dev/zero. Affected versions
0.0.1
0.0.2
1.3.1
1.3.2
1.4.0
1.8.0
Fixed in
1.11.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.4.0
minor
1 CVE
CVE-2025-11849
GHSA-rmjr-87wv-gf87
PYSEC-2026-1603
Oct 17, 2025
Mammoth is vulnerable to Directory Traversal
Medium
Network
Low
None
Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth before 1.11.0; versions of the package org.zwobble.mammoth:mammoth before 1.11.0 are vulnerable to Directory Traversal due to the lack of path or file type validation when processing a docx file containing an image with an external link (r:link attribute instead of embedded r:embed). The library resolves the URI to a file path and after reading, the content is encoded as base64 and included in the HTML output as a data URI. An attacker can read arbitrary files on the system where the conversion is performed or cause an excessive resources consumption by crafting a docx file that links to special device files such as /dev/random or /dev/zero. Affected versions
0.0.1
0.0.2
1.3.1
1.3.2
1.4.0
1.8.0
Fixed in
1.11.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.3.2
patch
1 CVE
CVE-2025-11849
GHSA-rmjr-87wv-gf87
PYSEC-2026-1603
Oct 17, 2025
Mammoth is vulnerable to Directory Traversal
Medium
Network
Low
None
Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth before 1.11.0; versions of the package org.zwobble.mammoth:mammoth before 1.11.0 are vulnerable to Directory Traversal due to the lack of path or file type validation when processing a docx file containing an image with an external link (r:link attribute instead of embedded r:embed). The library resolves the URI to a file path and after reading, the content is encoded as base64 and included in the HTML output as a data URI. An attacker can read arbitrary files on the system where the conversion is performed or cause an excessive resources consumption by crafting a docx file that links to special device files such as /dev/random or /dev/zero. Affected versions
0.0.1
0.0.2
1.3.1
1.3.2
1.4.0
1.8.0
Fixed in
1.11.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
1.3.1
major
1 CVE
CVE-2025-11849
GHSA-rmjr-87wv-gf87
PYSEC-2026-1603
Oct 17, 2025
Mammoth is vulnerable to Directory Traversal
Medium
Network
Low
None
Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth before 1.11.0; versions of the package org.zwobble.mammoth:mammoth before 1.11.0 are vulnerable to Directory Traversal due to the lack of path or file type validation when processing a docx file containing an image with an external link (r:link attribute instead of embedded r:embed). The library resolves the URI to a file path and after reading, the content is encoded as base64 and included in the HTML output as a data URI. An attacker can read arbitrary files on the system where the conversion is performed or cause an excessive resources consumption by crafting a docx file that links to special device files such as /dev/random or /dev/zero. Affected versions
0.0.1
0.0.2
1.3.1
1.3.2
1.4.0
1.8.0
Fixed in
1.11.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.0.2
patch
1 CVE
CVE-2025-11849
GHSA-rmjr-87wv-gf87
PYSEC-2026-1603
Oct 17, 2025
Mammoth is vulnerable to Directory Traversal
Medium
Network
Low
None
Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth before 1.11.0; versions of the package org.zwobble.mammoth:mammoth before 1.11.0 are vulnerable to Directory Traversal due to the lack of path or file type validation when processing a docx file containing an image with an external link (r:link attribute instead of embedded r:embed). The library resolves the URI to a file path and after reading, the content is encoded as base64 and included in the HTML output as a data URI. An attacker can read arbitrary files on the system where the conversion is performed or cause an excessive resources consumption by crafting a docx file that links to special device files such as /dev/random or /dev/zero. Affected versions
0.0.1
0.0.2
1.3.1
1.3.2
1.4.0
1.8.0
Fixed in
1.11.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.0.1
initial
1 CVE
CVE-2025-11849
GHSA-rmjr-87wv-gf87
PYSEC-2026-1603
Oct 17, 2025
Mammoth is vulnerable to Directory Traversal
Medium
Network
Low
None
Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth before 1.11.0; versions of the package org.zwobble.mammoth:mammoth before 1.11.0 are vulnerable to Directory Traversal due to the lack of path or file type validation when processing a docx file containing an image with an external link (r:link attribute instead of embedded r:embed). The library resolves the URI to a file path and after reading, the content is encoded as base64 and included in the HTML output as a data URI. An attacker can read arbitrary files on the system where the conversion is performed or cause an excessive resources consumption by crafting a docx file that links to special device files such as /dev/random or /dev/zero. Affected versions
0.0.1
0.0.2
1.3.1
1.3.2
1.4.0
1.8.0
Fixed in
1.11.0
References
Updated Jul 07, 2026 · Source: OSV.dev |