Matrix Media Repo Untrusted File Format Thumbnailing Vulnerability Invoking External Decoders

Vulnerability

A vulnerability exists in Matrix Media Repo (MMR) versions prior to 1.3.8, allowing users to upload files that falsely claim to be SVG or JPEGXL. When these files are processed for thumbnails, they can trigger different decoders in ImageMagick. In certain ImageMagick installations, this could enable the execution of Ghostscript to decode the file, potentially leading to the execution of malicious code. Similarly, if MP4 thumbnailers are enabled, the issue could arise with the ffmpeg installation, exploiting the same flaw by uploading a file that pretends to be an MP4.

Impact

Exploitation of this vulnerability could lead to the execution of untrusted code through Ghostscript or ffmpeg, depending on the file type uploaded.

Remediation

Users are advised to upgrade to Matrix Media Repo version 1.3.8 or later. For those unable to upgrade, the SVG, JPEGXL, and MP4 thumbnail types can be disabled in the MMR configuration. Additionally, using containers or similar technologies can help mitigate the impact of vulnerabilities in external decoders like ImageMagick and ffmpeg.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
10.0
exploitability
5.0
remediation
8.3
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.