Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-28103

25
FAUCET Score

CVE-2023-28103 is a high-severity denial-of-service vulnerability affecting matrix-react-sdk, a Matrix chat protocol SDK for React Javascript. Remote servers can send specially crafted data that modifies Object.prototype, disrupting functionality and potentially altering program logic. With a CVSS score of 8.2 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H), this vulnerability is easily exploitable over the network with low attack complexity, leading to high availability impact. There is currently no evidence of active exploitation, no known exploit code, and minimal community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.69.0CPE matchmatch criteria
cpe:2.3:a:matrix-react-sdk_project:matrix-react-sdk:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

8.2HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
4.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.71%
Probability of exploitation in next 30 days
EPSS Percentile
49.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0071 is in the 26th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

harborpatch availablevia llm_extracted
Fixed in: matrix-js-sdk 20.0.0, matrix-react-sdk 3.54.0
View patch
netgearpatch availablevia llm_extracted
Fixed in: matrix-react-sdk 3.60.0
View patch
npmpatch availablevia ghsa
Product: matrix-react-sdkFixed in: 3.69.0
phoenix_contactpatch availablevia llm_extracted
View patch
github_advisoryvendor investigatingvia nvd_reference
View patch

Vendor Advisories (4)

npmGHSA-6g43-88cp-w5gvhigh

Prototype pollution in matrix-react-sdk

Mar 29, 2023
harborllm-harbor-ee0543034c51d3d4HIGH

High Severity Prototype Pollution Vulnerabilities in matrix-js-sdk and matrix-react-sdk

Mar 29, 2023
netgearllm-netgear-e5d052ca8a3241adHIGH

Prototype Pollution in matrix-react-sdk

Mar 29, 2023
phoenix_contactllm-phoenix_contact-9abfaf72a2822a0bHIGH

High-severity Prototype Pollution vulnerabilities in matrix-js-sdk and matrix-react-sdk

Mar 29, 2023

References

github.com / matrix-org/matrix-react-sdk/security/advisories/GHSA-6g43-88cp-w5gv
Vendor Advisory
matrix.org / blog/2023/03/28/security-releases-matrix-js-sdk-24-0-0-and-matrix-react-sdk-3-69-0
Vendor Advisory