Vulnerabilities/

Matrix IRC Bridge allows IRC command injection to own puppeted user

Severity:
Low

Description

The matrix-appservice-irc bridge up to version 3.0.3 contains a vulnerability which can lead to arbitrary IRC command execution as the puppeted user. The attacker can only inject commands executed as their own IRC user.

Recommendation

Update the matrix-appservice-irc package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
matrix-appservice-irc
Anything's wrong? Let us know Last updated on February 25, 2025

This issue is available in SmartScanner Professional

See Pricing