LOW2.7
GHSA-5mvm-89c9-9gm5
Matrix IRC Bridge allows IRC command injection to own puppeted user
Quick fix
GHSA-5mvm-89c9-9gm5 — matrix-appservice-irc: upgrade to the fixed version with the command below.
npm install matrix-appservice-irc@3.0.4Details
### Impact The matrix-appservice-irc bridge up to version 3.0.3 contains a vulnerability which can lead to arbitrary IRC command execution as the puppeted user. The attacker can only inject commands executed as their own IRC user.
### Patches The vulnerability has been patched in matrix-appservice-irc version 3.0.4.
### For more information If you have any questions or comments about this advisory, please email us at [security at matrix.org](mailto:security@matrix.org).
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/matrix-org/matrix-appservice-irc/security/advisories/GHSA-5mvm-89c9-9gm5[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-27146[ADVISORY]
- https://github.com/matrix-org/matrix-appservice-irc/commit/74f02c8e11f16ed1b355700092c1aa9c036a11bd[WEB]
- https://github.com/matrix-org/matrix-appservice-irc[PACKAGE]