Vulnerabilities/

matrix-js-sdk has insufficient MXC URI validation which allows client-side path traversal

Severity:
Medium

Description

matrix-js-sdk before 34.11.0 is vulnerable to client-side path traversal via crafted MXC URIs. A malicious room member can trigger clients based on the matrix-js-sdk to issue arbitrary authenticated GET requests to the client’s homeserver.

Recommendation

Update the matrix-js-sdk package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
matrix-js-sdk
Anything's wrong? Let us know Last updated on November 12, 2024

This issue is available in SmartScanner Professional

See Pricing