CVE-2025-27146

LOW2.7EPSS 0.75%

Matrix IRC Bridge allows IRC command injection to own puppeted user

Published: 2/25/2025Modified: 2/25/2025
Also known as:GHSA-5mvm-89c9-9gm5

Description

### Impact The matrix-appservice-irc bridge up to version 3.0.3 contains a vulnerability which can lead to arbitrary IRC command execution as the puppeted user. The attacker can only inject commands executed as their own IRC user. ### Patches The vulnerability has been patched in matrix-appservice-irc version 3.0.4. ### For more information If you have any questions or comments about this advisory, please email us at [security at matrix.org](mailto:[email protected]).

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1LOW2.7CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N

References (4)