VDB
Sign up
LOW2.7

GHSA-5mvm-89c9-9gm5

Matrix IRC Bridge allows IRC command injection to own puppeted user

Quick fix

GHSA-5mvm-89c9-9gm5 — matrix-appservice-irc: upgrade to the fixed version with the command below.

npm install matrix-appservice-irc@3.0.4

Details

### Impact The matrix-appservice-irc bridge up to version 3.0.3 contains a vulnerability which can lead to arbitrary IRC command execution as the puppeted user. The attacker can only inject commands executed as their own IRC user.

### Patches The vulnerability has been patched in matrix-appservice-irc version 3.0.4.

### For more information If you have any questions or comments about this advisory, please email us at [security at matrix.org](mailto:security@matrix.org).

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/matrix-appservice-irc
Introduced in: 0Fixed in: 3.0.4
Fixnpm install matrix-appservice-irc@3.0.4

References