matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains a vulnerability which can lead to arbitrary IRC command execution as the puppeted user. The attacker can only inject commands executed as their own IRC user. The vulnerability has been patched in matrix-appservice-irc version 3.0.4.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Mar 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Matrix
Matrix matrix Irc Bridge |
|
CPEs | cpe:2.3:a:matrix:matrix_irc_bridge:*:*:*:*:*:node.js:*:* | |
Vendors & Products |
Matrix
Matrix matrix Irc Bridge |
Tue, 25 Feb 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 25 Feb 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains a vulnerability which can lead to arbitrary IRC command execution as the puppeted user. The attacker can only inject commands executed as their own IRC user. The vulnerability has been patched in matrix-appservice-irc version 3.0.4. | |
Title | Matrix IRC Bridge allows IRC command injection to own puppeted user | |
Weaknesses | CWE-77 CWE-88 |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-02-25T20:04:40.400Z
Updated: 2025-02-25T20:33:36.095Z
Reserved: 2025-02-19T16:30:47.778Z
Link: CVE-2025-27146

Updated: 2025-02-25T20:30:57.833Z

Status : Analyzed
Published: 2025-02-25T20:15:38.030
Modified: 2025-03-04T20:42:55.570
Link: CVE-2025-27146

No data.