CVE-2022-39250 is a high-severity vulnerability affecting the Matrix JavaScript SDK prior to version 19.7.0. It allows a malicious homeserver, in coordination with an attacker, to inject a false cross-signing user identity during the verification flow, leading to users trusting an attacker-controlled identity instead of the legitimate one. With a CVSS score of 7.5 (High), this vulnerability has a network attack vector and low attack complexity, resulting in a high impact on integrity (I:H). While it requires a malicious homeserver, the vulnerability could compromise the authenticity of user identities within the Matrix ecosystem. There is no evidence of active exploitation, and no public exploit code is available in Metasploit, Nuclei, or ExploitDB. However, the vulnerability has garnered community attention with one mention and one media article, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 19.7.0CPE matchmatch criteria | cpe:2.3:a:matrix:javascript_sdk:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.