mammoth is vulnerable to Uncontrolled Recursion
53
Medium Risk
The numbering parser resolves a numbering definition's numStyleLink by following it to another numbering style and recursing into that style. A crafted document whose numbering styles reference one another, or a style that references itself, makes this resolution recurse without ever terminating. Converting such a document exhausts the call stack and aborts the conversion, denying service for that input. The fix records already-visited numbering IDs and stops when a cycle is detected.
You are affected if you are using a version that falls within the vulnerable range and your application converts untrusted .docx documents, via either the library convert API or the command-line interface.
mammoth is vulnerable to Uncontrolled Recursion in versions 1.4.9 - 1.12.0.
Upgrade the mammoth library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant