CVE-2024-42347
matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages would be sent to the server. This was patched in matrix-react-sdk 3.105.0. Deployments that trust their homeservers, as well as closed federations of trusted servers, are not affected. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.7
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
- EPSS probability
- 0.43%
- CWE
- CWE-359
- Published
- 2024-08-06
- Last modified
- 2026-03-13
Affected products
- matrix-org matrix-react-sdk
Weakness type
Related vulnerabilities
- CVE-2026-88875 — AVideo Incomplete API Sanitization Information Disclosure
- CVE-2026-73008 — Windows Biometric Service Information Disclosure Vulnerability
- CVE-2026-69351 — Windows Universal Plug and Play (UPnP) Device Host Information Disclosure Vulnerability
- CVE-2026-21827 — HCL Connections is vulnerable to an information disclosure vulnerability
- CVE-2026-53497 — CrossWatch: Unauthenticated /api/app-auth/status endpoint leaks active session metadata (IP, User-Agent, session IDs)
- CVE-2026-58510 — GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private
- CVE-2026-48048 — XWiki Platform's Livetable results still allow reconstructing password hashes using 768 requests
- CVE-2026-24078 — Exposure of Private Personal Information to an Unauthorized Actor in Data Modem