mammoth is vulnerable to Path Traversal
59
Medium Risk
The command-line interface writes extracted document images into the directory given by --output-dir, deriving each image file extension from the content type declared inside the document. On Windows a content type that contains backslash path segments is used unmodified, so the generated image filename can contain directory separators and traversal segments. Converting a crafted document then writes image files outside the intended output directory. The fix derives the extension by splitting the content type on both forward and back slashes so it can no longer contain path separators.
You are affected if you are using a version that falls within the vulnerable range and you run the command-line interface with --output-dir on Windows to convert untrusted documents.
mammoth is vulnerable to Path Traversal in versions 0.1.2 - 1.12.0.
Upgrade the mammoth library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant