Mjolnir Moderation Tool for Matrix Command Execution Vulnerability

Vulnerability

A vulnerability in the Mjolnir moderation tool for Matrix, specifically in version 1.9.0, allows the bot to respond to management commands from any room it is a member of. This issue can enable users who are not bot operators to access the bot's functions, including server administration components if activated. The vulnerability arises from a feature that improperly manages command responses based on room membership.

Impact

Exploitation of this vulnerability could lead to unauthorized users executing management commands through the bot, potentially allowing them to perform administrative tasks on the server.

Reproduction

To reproduce this vulnerability, invite the Mjolnir bot to a room and have a non-operator user send a management command. The bot will respond to the command, demonstrating the unauthorized access.

Remediation

Users can upgrade to Mjolnir version 1.9.1 or 1.9.2, which address the vulnerability. If an upgrade is not possible, downgrading to version 1.8.3 is recommended.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.7
remediation
7.7
relevance
0.0
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.