Vulnerabilities/

Improper handling of multiline messages in node-irc affects matrix-appservice-irc

Severity:
High

Description

matrix-appservice-irc provides an IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate a Matrix user into executing IRC commands by having them reply to a maliciously crafted message. The vulnerability has been patched in matrix-appservice-irc 0.33.2.

Recommendation

Update the matrix-appservice-irc package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
matrix-appservice-irc
Anything's wrong? Let us know Last updated on January 27, 2023

This issue is available in SmartScanner Professional

See Pricing