VDB
Sign up
MEDIUM

GHSA-mp7c-m3rh-r56v

matrix-js-sdk has insufficient validation when considering a room to be upgraded by another

Quick fix

GHSA-mp7c-m3rh-r56v — matrix-js-sdk: upgrade to the fixed version with the command below.

npm install matrix-js-sdk@38.2.0

Details

### Impact matrix-js-sdk before 38.2.0 has insufficient validation of room predecessor links in `MatrixClient::getJoinedRooms`, allowing a remote attacker to attempt to replace a tombstoned room with an unrelated attacker-supplied room.

### Patches The issue has been patched and users should upgrade to 38.2.0.

### Workarounds Avoid using `MatrixClient::getJoinedRooms` in favour of `getRooms()` and filtering upgraded rooms separately.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/matrix-js-sdk
Introduced in: 0Fixed in: 38.2.0
Fixnpm install matrix-js-sdk@38.2.0

References