Description
Versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth from 0.3.25 and before 1.11.0; versions of the package mammoth before 1.11.0; versions of the package org.zwobble.mammoth:mammoth before 1.11.
Recommendation
Update the mammoth package to the latest compatible version. Followings are version details:
- Affected version(s): >= 0.3.25, < 1.11.0
- Patched version(s): 1.11.0
References
Could your website be exposed too?
SmartScanner can check your website for Mammoth is vulnerable to Directory Traversal and gives you actionable findings to investigate.
Start a free scanRelated Issues
- nanotar is vulnerable to path traversal in parseTar() and parseTarGzip() - CVE-2025-69874
- MJML allows mj-include directory traversal due to an incomplete fix for CVE-2020-12827 - CVE-2025-67898
- jqueryFileTree vulnerable to Directory Traversal - CVE-2017-1000170
- Agnai vulnerable to Remote Code Execution via JS Upload using Directory Traversal - CVE-2024-47169


