matrix-appservice-irc
cpe:2.3:a:matrix:matrix_irc_bridge:*:*:*:*:node.js:*:*
- < 3.0.4
A vulnerability in the Node.js IRC bridge for Matrix, matrix-appservice-irc, prior to version 3.0.4, allows for arbitrary execution of IRC commands as the puppeted user. This exploitation is limited to commands being executed as the user's own IRC identity.
Exploitation of this vulnerability could lead to unauthorized execution of IRC commands, potentially allowing for manipulation of IRC interactions or environments as the affected user.
Users can upgrade to matrix-appservice-irc version 3.0.4 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.