🚨 CVE-2026-105219
Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in lib/styles/parser/tokeniser.js due to overlapping regex alternatives. Attackers can supply a crafted .docx with an unterminated quoted string of repeated backslash escapes in mammoth/style-map to block the Node.js event loop.
🎖@cveNotify

GitHub
GitHub - mwilliamson/mammoth.js: Convert Word documents (.docx files) to HTML
Convert Word documents (.docx files) to HTML. Contribute to mwilliamson/mammoth.js development by creating an account on GitHub.
October 4, 2026 114