Junglewise Threat Intelligence

CVE-2025-11849: PYSEC-2026-1603 - Mammoth is vulnerable to Directory Traversal

CVE-2025-11849 · Severity: low · CVSS 3.1 · Published 2026-07-07

Vendors: Maven, PyPI, npm.

Executive brief

Mammoth is a document conversion library used to transform Word documents (.docx files) into HTML. The vulnerability allows an attacker to read arbitrary files from the system or cause excessive resource consumption by crafting a malicious Word document with images that reference external file paths instead of embedded content. This could lead to exposure of sensitive data or system unavailability.

Technical details

The vulnerability is a path traversal flaw (CWE-22) in how Mammoth processes images within docx files. When a docx contains an image with an external link attribute (r:link) instead of an embedded resource (r:embed), the library resolves the URI to a file path and reads the content without validating the path or file type. The attacker-controlled file content is then base64-encoded and embedded in the HTML output as a data URI. The attack requires the attacker to supply a crafted docx file to be converted; no authentication is needed, though user interaction (document upload/processing) is typically required. An attacker can read arbitrary files on the system or cause denial-of-service by linking to special device files like /dev/random or /dev/zero. The fix was released in version 1.11.0 by disabling external file access by default.

Affected products

  • Mammoth mammoth 0.3.25 to <1.11.0
  • Mammoth mammoth <1.11.0
  • Mammoth Mammoth <1.11.0
  • Mammoth mammoth <1.11.0

Timeline

  • 2025-10-17: disclosed: Advisory published (GHSA-rmjr-87wv-gf87)
  • 2025-10-17: patched: Fix released in version 1.11.0

References