GHSA-cg57-p69r-3m7p

Suggest an improvement
Source
https://github.com/advisories/GHSA-cg57-p69r-3m7p
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-cg57-p69r-3m7p/GHSA-cg57-p69r-3m7p.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-cg57-p69r-3m7p
Aliases
Published
2022-02-10T23:46:51Z
Modified
2026-07-08T06:49:32Z
Severity
  • 4.2 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L CVSS Calculator
Summary
Improper file handling in matrix-react-sdk
Details

Matrix-React-SDK is a react-based SDK for inserting a Matrix chat/voip client into a web page. Before version 3.21.0, when uploading a file, the local file preview can lead to execution of scripts embedded in the uploaded file. This can only occur after several user interactions to open the preview in a separate tab. This only impacts the local user while in the process of uploading. It cannot be exploited remotely or by other users. This vulnerability is patched in version 3.21.0.

Database specific
{
    "cwe_ids":  [
        "CWE-434",
        "CWE-74"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2021-05-19T17:48:44Z",
    "nvd_published_at":  "2021-05-17T20:15:00Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / matrix-react-sdk

Package

Name
matrix-react-sdk
View open source insights on deps.dev
Purl
pkg:npm/matrix-react-sdk

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
3.21.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-cg57-p69r-3m7p/GHSA-cg57-p69r-3m7p.json"