Impact
Mammoth.js versions 1.3.0 through 1.12.2 contain a regular expression denial‑of‑service vulnerability in the style map tokeniser. The overlapping regex alternatives cause catastrophic backtracking when parsing an unterminated quoted string of repeated backslashes, which blocks the Node.js event loop and makes the application unresponsive. This flaw is a classic RegEx ReDoS weakness, classified as CWE‑1333.
Affected Systems
The vulnerability affects the open‑source library mammoth.js distributed by David Williamson. Versions from 1.3.0 up to, but not including, 1.12.3 are impacted. Any project that imports or bundles these versions and processes .docx files supplied by external or untrusted sources is at risk.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity and the lack of an EPSS score or KEV listing does not diminish the risk, especially for applications that parse Office files. Based on the description, the likely attack vector is by supplying a malicious .docx file, which can be performed remotely where the library is invoked, such as in web services or command‑line tools that accept user uploads. An attacker who can supply and trigger the regex backtracking consumes CPU time and halts the Node.js event loop, leading to denial of service across the application.
OpenCVE Enrichment