Events sent with special strings in key places can temporarily disrupt or impede the matrix-react-sdk from functioning properly, such as by causing room or event tile crashes. The remainder of the application can appear functional, though certain rooms/events will not be rendered.
This is fixed in matrix-react-sdk 3.53.0
There are no workarounds. Please upgrade immediately.
https://learn.snyk.io/lessons/prototype-pollution/javascript/
If you have any questions or comments about this advisory please email us at security at matrix.org.
{
"cwe_ids": [
"CWE-1321"
],
"github_reviewed": true,
"github_reviewed_at": "2023-03-28T19:57:57Z",
"nvd_published_at": "2023-03-28T21:15:00Z",
"severity": "HIGH"
}