CVE-2024-50336

MEDIUM

matrix-js-sdk < 34.11.1 - Path Traversal via Crafted MXC URIs

Title source: llm
STIX 2.1

Description

matrix-js-sdk is a Matrix messaging protocol Client-Server SDK for JavaScript. matrix-js-sdk before 34.11.0 is vulnerable to client-side path traversal via crafted MXC URIs. A malicious room member can trigger clients based on the matrix-js-sdk to issue arbitrary authenticated GET requests to the client's homeserver. Fixed in matrix-js-sdk 34.11.1.

Scores

CVSS v4 5.3
EPSS 0.0088
EPSS Percentile 75.5%
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (2)
matrix-org/matrix-js-sdk < 34.11.1
npm/matrix-js-sdk 0 - 34.11.1npm
Published Nov 12, 2024
Tracked Since Feb 18, 2026