t2bot matrix-media-repo
cpe:2.3:a:matrix-media-repo_project:matrix-media-repo:*:*:*:*:*:*:*
- < 1.3.8
A vulnerability exists in Matrix Media Repo (MMR) versions prior to 1.3.8, allowing users to upload files that falsely claim to be SVG or JPEGXL. When these files are processed for thumbnails, they can trigger different decoders in ImageMagick. In certain ImageMagick installations, this could enable the execution of Ghostscript to decode the file, potentially leading to the execution of malicious code. Similarly, if MP4 thumbnailers are enabled, the issue could arise with the ffmpeg installation, exploiting the same flaw by uploading a file that pretends to be an MP4.
Exploitation of this vulnerability could lead to the execution of untrusted code through Ghostscript or ffmpeg, depending on the file type uploaded.
Users are advised to upgrade to Matrix Media Repo version 1.3.8 or later. For those unable to upgrade, the SVG, JPEGXL, and MP4 thumbnail types can be disabled in the MMR configuration. Additionally, using containers or similar technologies can help mitigate the impact of vulnerabilities in external decoders like ImageMagick and ffmpeg.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.