VDB
Sign up
MEDIUM6.1

GHSA-c9vx-2g7w-rp65

matrix-react-sdk vulnerable to XSS in Export Chat feature

Quick fix

GHSA-c9vx-2g7w-rp65 — matrix-react-sdk: upgrade to the fixed version with the command below.

npm install matrix-react-sdk@3.76.0

Details

### Description

The Export Chat feature includes certain attacker-controlled elements in the generated document without sufficient escaping, leading to stored XSS.

### Impact

Since the Export Chat feature generates a separate document, an attacker can only inject code run from the `null` origin, restricting the impact.

However, the attacker can still potentially use the XSS to leak message contents. A malicious homeserver is a potential attacker since the affected inputs are controllable server-side.

### Patches This was patched in matrix-react-sdk 3.76.0.

### Workarounds None, other than not using the Export Chat feature.

### References N/A

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/matrix-react-sdk
Introduced in: 3.32.0Fixed in: 3.76.0
Fixnpm install matrix-react-sdk@3.76.0

References