matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains a vulnerability which can lead to arbitrary IRC command execution as the puppeted user. The attacker can only inject commands executed as their own IRC user. The vulnerability has been patched in matrix-appservice-irc version 3.0.4.
References
Configurations
History
04 Mar 2025, 20:42
Type | Values Removed | Values Added |
---|---|---|
First Time |
Matrix
Matrix matrix Irc Bridge |
|
CPE | cpe:2.3:a:matrix:matrix_irc_bridge:*:*:*:*:*:node.js:*:* | |
Summary |
|
|
References | () https://github.com/matrix-org/matrix-appservice-irc/commit/74f02c8e11f16ed1b355700092c1aa9c036a11bd - Patch | |
References | () https://github.com/matrix-org/matrix-appservice-irc/security/advisories/GHSA-5mvm-89c9-9gm5 - Vendor Advisory |
25 Feb 2025, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-25 20:15
Updated : 2025-03-04 20:42
NVD link : CVE-2025-27146
Mitre link : CVE-2025-27146
CVE.ORG link : CVE-2025-27146
JSON object : View
Products Affected
matrix
- matrix_irc_bridge