VYPR

Matrix Irc Bridge

by Matrix Org

Source repositories

CVEs (7)

  • CVE-2022-39203HigSep 13, 2022
    risk 0.57cvss 8.8epss 0.01

    matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. Attackers can specify a specific string of characters, which would confuse the bridge into combining an attacker-owned channel and an existing channel, allowing them to grant themselves permissions in the…

  • CVE-2022-29166HigMay 5, 2022
    risk 0.52cvss 8.0epss 0.01

    matrix-appservice-irc is a Node.js IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate a Matrix user into executing IRC commands by having them reply to a maliciously crafted message. The vulnerability has been patched in matrix-appservice-irc…

  • CVE-2023-38690MedAug 4, 2023
    risk 0.31cvss 5.8epss 0.01

    matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it is possible to craft a command with newlines which would not be properly parsed. This would mean you could pass a string of commands as a channel name, which would then be run by the IRC bridge…

  • CVE-2022-3971MedNov 13, 2022
    risk 0.23cvss 4.6epss 0.01

    A vulnerability was found in matrix-appservice-irc up to 0.35.1. It has been declared as critical. This vulnerability affects unknown code of the file src/datastore/postgres/PgDataStore.ts. The manipulation of the argument roomIds leads to sql injection. Upgrading to version…

  • CVE-2022-39202MedSep 13, 2022
    risk 0.21cvss 4.3epss 0.01

    matrix-appservice-irc is an open source Node.js IRC bridge for Matrix. The Internet Relay Chat (IRC) protocol allows you to specify multiple modes in a single mode command. Due to a bug in the underlying matrix-org/node-irc library, affected versions of matrix-appservice-irc…

  • CVE-2023-38700LowAug 4, 2023
    risk 0.16cvss 3.5epss 0.01

    matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it was possible to craft an event such that it would leak part of a targeted message event from another bridged room. This required knowing an event ID to target. Version 1.0.1n fixes this issue.…

  • CVE-2025-27146LowFeb 25, 2025
    risk 0.11cvss 2.7epss 0.00

    matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains a vulnerability which can lead to arbitrary IRC command execution as the puppeted user. The attacker can only inject commands executed as their own IRC user.…