VDB
Sign up
HIGH8.0

GHSA-52rh-5rpj-c3w6

Improper handling of multiline messages in node-irc

Quick fix

GHSA-52rh-5rpj-c3w6 — matrix-org-irc: upgrade to the fixed version with the command below.

npm install matrix-org-irc@1.2.1

Details

node-irc is a socket wrapper for the IRC protocol that extends Node.js' EventEmitter. The vulnerability allows an attacker to manipulate a Matrix user into executing IRC commands by having them reply to a maliciously crafted message. Incorrect handling of a CR character allowed for making part of the message be sent to the IRC server verbatim rather than as a message to the channel. The vulnerability has been patched in node-irc version 1.2.1.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/matrix-org-irc
Introduced in: 0Fixed in: 1.2.1
Fixnpm install matrix-org-irc@1.2.1

References