CVE-2023-38690 is a critical vulnerability affecting matrix-appservice-irc, a Node.js IRC bridge for Matrix, prior to version 1.0.1. An attacker can craft commands with newlines within a channel name, leading to arbitrary command execution on the IRC bridge bot. This vulnerability carries a CVSS score of 9.8 (CRITICAL) due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While there are no robust workarounds, disabling dynamic channels can mitigate the most common exploitation method. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.1CPE matchmatch criteria | cpe:2.3:a:matrix:matrix_irc_bridge:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
matrix-appservice-irc IRC command injection via admin commands containing newlines
Aug 4, 2023IRC command injection via admin commands containing newlines
Jul 26, 2023Multiple High Severity Vulnerabilities in Matrix Bridges
Jul 12, 2023Security Updates for Matrix Bridges: OpenID Token Exchange, IRC Command Injection, and Message Leak Vulnerabilities
Jul 10, 2023