MEDIUM6.5npm
GHSA-35g4-qx3c-vjhx· CVE-2021-32659Automatic room upgrade handling can be used maliciously to bridge a room non-consentually
Modified: 7/8/2026
package
pkg:npm/matrix-appservice-bridge
Automatic room upgrade handling can be used maliciously to bridge a room non-consentually
Modified: 7/8/2026
matrix-appservice-bridge doesn't verify the sub parameter of an openId token exhange, allowing unauthorized access to provisioning APIs
Modified: 9/10/2026