CVE-2025-27146

LOW

matrix-appservice-irc <3.0.3 - Command Injection

Title source: llm

Description

matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains a vulnerability which can lead to arbitrary IRC command execution as the puppeted user. The attacker can only inject commands executed as their own IRC user. The vulnerability has been patched in matrix-appservice-irc version 3.0.4.

Scores

CVSS v3 2.7
EPSS 0.0036
EPSS Percentile 57.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

Classification

CWE
CWE-88 CWE-77
Status published

Affected Products (2)

matrix/matrix_irc_bridge < 3.0.4
npm/matrix-appservice-irc < 3.0.4npm

Timeline

Published Feb 25, 2025
Tracked Since Feb 18, 2026