CVE-2025-24024

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-24024
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-24024.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-24024
Aliases
  • GHSA-3jq6-xc85-m394
Published
2025-01-21T20:15:46Z
Modified
2025-01-22T08:58:57.810541Z
Summary
[none]
Details

Mjolnir is a moderation tool for Matrix. Mjolnir v1.9.0 responds to management commands from any room the bot is member of. This can allow users who aren't operators of the bot to use the bot's functions, including server administration components if enabled. Version 1.9.1 reverts the feature that introduced the bug, and version 1.9.2 reintroduces the feature safely. Downgrading to version 1.8.3 is recommended if upgrading to 1.9.1 or higher isn't possible.

References

Affected packages

Git / github.com/matrix-org/mjolnir

Affected ranges

Type
GIT
Repo
https://github.com/matrix-org/mjolnir
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

v0.*

v0.1.0
v0.1.1
v0.1.10
v0.1.11
v0.1.12
v0.1.13
v0.1.14
v0.1.15
v0.1.16
v0.1.17
v0.1.18
v0.1.19
v0.1.2
v0.1.3
v0.1.4
v0.1.5
v0.1.6
v0.1.7
v0.1.8
v0.1.9

v1.*

v1.1.20
v1.1.21
v1.2.1
v1.3.0
v1.3.1
v1.3.2
v1.4.0
v1.4.1
v1.4.2
v1.5.0
v1.6.0
v1.6.1
v1.6.2
v1.6.3
v1.6.4
v1.6.5
v1.7.0
v1.8.0
v1.8.1
v1.8.2
v1.8.3
v1.9.0
v1.9.1