Events sent with special strings in key places can temporarily disrupt or impede the matrix-react-sdk from functioning properly, such as by causing room or event tile crashes. The remainder of the application can appear functional, though certain rooms/events will not be rendered.
This is fixed in matrix-react-sdk 3.53.0
There are no workarounds. Please upgrade immediately.
https://learn.snyk.io/lessons/prototype-pollution/javascript/
If you have any questions or comments about this advisory please email us at security at matrix.org.
{ "github_reviewed": true, "cwe_ids": [ "CWE-1321" ], "severity": "HIGH", "github_reviewed_at": "2023-03-28T19:57:57Z", "nvd_published_at": "2023-03-28T21:15:00Z" }