CVE-2024-52505
matrix-appservice-irc is a Node.js IRC bridge for the Matrix messaging protocol. The provisioning API of the matrix-appservice-irc bridge up to version 3.0.2 contains a vulnerability which can lead to arbitrary IRC command execution as the bridge IRC bot. The vulnerability has been patched in matrix-appservice-irc version 3.0.3.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.4
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- EPSS probability
- 0.38%
- CWE
- CWE-147
- Published
- 2024-11-14
- Last modified
- 2026-03-13
Affected products
- matrix-org matrix-appservice-irc
Weakness type
Related vulnerabilities
- CVE-2025-7962 — In Jakarta Mail 2.0.2 it is possible to preform a SMTP Injection by utilizing the \r and \n UTF-8...
- CVE-2024-50349 — Git does not sanitize URLs when asking for credentials interactively
- CVE-2024-52006 — Newline confusion in credential helpers can lead to credential exfiltration in git
- CVE-2023-4393 — HTML and SMTP Injection in LiquidFiles