CVE-2022-29166

HIGH

matrix-appservice-irc <0.33.2 - RCE

Title source: llm
STIX 2.1

Description

matrix-appservice-irc is a Node.js IRC bridge for Matrix. The vulnerability in node-irc allows an attacker to manipulate a Matrix user into executing IRC commands by having them reply to a maliciously crafted message. The vulnerability has been patched in matrix-appservice-irc 0.33.2. Refrain from replying to messages from untrusted participants in IRC-bridged Matrix rooms. There are no known workarounds for this issue.

References (2)

Core 2

Scores

CVSS v3 8.0
EPSS 0.0051
EPSS Percentile 66.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-74
Status published
Products (2)
matrix/matrix_irc_bridge < 0.33.2
npm/matrix-appservice-irc 0 - 0.33.2npm
Published May 05, 2022
Tracked Since Feb 18, 2026