CVE-2025-27146

LOW

matrix-appservice-irc <3.0.3 - Command Injection

Title source: llm
STIX 2.1

Description

matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains a vulnerability which can lead to arbitrary IRC command execution as the puppeted user. The attacker can only inject commands executed as their own IRC user. The vulnerability has been patched in matrix-appservice-irc version 3.0.4.

Scores

CVSS v3 2.7
EPSS 0.0075
EPSS Percentile 73.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-88 CWE-77
Status published
Products (2)
matrix/matrix_irc_bridge < 3.0.4
npm/matrix-appservice-irc 0 - 3.0.4npm
Published Feb 25, 2025
Tracked Since Feb 18, 2026