CVE-2023-28103

HIGH

Matrix-react-sdk < 3.69.0 - Prototype Pollution

Title source: rule
STIX 2.1

Description

matrix-react-sdk is a Matrix chat protocol SDK for React Javascript. In certain configurations, data sent by remote servers containing special strings in key locations could cause modifications of the `Object.prototype`, disrupting matrix-react-sdk functionality, causing denial of service and potentially affecting program logic. This is fixed in matrix-react-sdk 3.69.0 and users are advised to upgrade. There are no known workarounds for this vulnerability. Note this advisory is distinct from GHSA-2x9c-qwgf-94xr which refers to a similar issue.

Scores

CVSS v3 8.2
EPSS 0.0060
EPSS Percentile 69.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-1321
Status published
Products (2)
matrix-react-sdk_project/matrix-react-sdk < 3.69.0
npm/matrix-react-sdk 0 - 3.69.0npm
Published Mar 28, 2023
Tracked Since Feb 18, 2026