Matrix Media Repo Unauthenticated Content Injection Vulnerability

Vulnerability

A vulnerability in Matrix Media Repo (MMR) versions prior to 1.3.5 allows unauthenticated remote participants to download and cache media from a remote homeserver to the local media repository. This content can then be accessed from the local homeserver without authentication. As a result, unauthenticated remote adversaries can exploit this feature to introduce undesirable content into the media repository.

Impact

Exploitation of this vulnerability allows for the injection of problematic content into the media repository, which can be accessed unauthenticated from the local homeserver.

Remediation

Users can update to Matrix Media Repo version 1.3.5 or later, which introduces authenticated endpoints for media downloads. The unauthenticated endpoints will be deprecated in a future release. Server operators can also implement stricter rate limits based on IP address as a temporary workaround.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
2.5
exploitability
8.1
remediation
7.9
relevance
0.0
threat
0.0
urgency
2.9
incentive
10.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.