Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-38691

19
FAUCET Score

CVE-2023-38691 is a medium-severity vulnerability affecting matrix-appservice-bridge versions 4.0.0 through 8.1.1 and 9.0.0. A malicious Matrix server can impersonate users via the provisioning API by manipulating the OpenID exchange, specifically by providing a false servername in the 'sub' parameter. This allows an attacker to perform provisioning requests on behalf of other users, leading to a high impact on confidentiality. The vulnerability has a CVSS score of 6.5, indicating a network attack vector with low complexity and no user interaction required. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.0.0, < 8.1.2CPE matchmatch criteria
cpe:2.3:a:matrix:matrix-appservice-bridge:*:*:*:*:*:node.js:*:*
9.0.0CPE matchmatch criteria
cpe:2.3:a:matrix:matrix-appservice-bridge:9.0.0:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

5.0MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
3.1
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.39%
Probability of exploitation in next 30 days
EPSS Percentile
31.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0039 is in the 41st percentile among its peer group of 21,974 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

github_advisorypatch availablevia nvd_reference
View patch
harborpatch availablevia llm_extracted
Fixed in: matrix-appservice-irc 1.0.1, matrix-hookshot 4.4.1, matrix-appservice-slack 2.1.2, matrix-appservice-bridge 9.0.1 (and 8.1.2)
View patch
netgearpatch availablevia llm_extracted
Fixed in: matrix-appservice-bridge 9.0.1 (and 8.1.2), matrix-appservice-irc 1.0.1, matrix-hookshot 4.4.1, matrix-appservice-slack 2.1.2
View patch
npmpatch availablevia ghsa
Product: matrix-appservice-bridgeFixed in: 8.1.2
npmpatch availablevia ghsa
Product: matrix-appservice-bridgeFixed in: 9.0.1
phoenix_contactpatch availablevia llm_extracted
Fixed in: matrix-appservice-irc 1.0.1, matrix-hookshot 4.4.1, matrix-appservice-slack 2.1.2, matrix-appservice-bridge 9.0.1 (and 8.1.2)
View patch

Vendor Advisories (4)

npmGHSA-vc7j-h8xg-fv5xmedium

matrix-appservice-bridge doesn't verify the sub parameter of an openId token exhange, allowing unauthorized access to provisioning APIs

Aug 4, 2023
netgearllm-netgear-9d263ff685fa0427MEDIUM

matrix-appservice-bridge doesn't verify the sub parameter of an openId token exchange

Jul 26, 2023
harborllm-harbor-1670ef3d989ba299HIGH

Multiple High Severity Vulnerabilities in Matrix Bridges

Jul 12, 2023
phoenix_contactllm-phoenix_contact-c12d9603f79c2712HIGH

Security Updates for Matrix Bridges: OpenID Token Exchange, IRC Command Injection, and Message Leak Vulnerabilities

Jul 10, 2023

References

github.com / matrix-org/matrix-appservice-bridge/commit/4c6723a5e7beda65cdf1ae5dbb882e8beaac8552
Patch
github.com / matrix-org/matrix-appservice-bridge/security/advisories/GHSA-vc7j-h8xg-fv5x
Third Party Advisory