Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-38700

14
FAUCET Score

CVE-2023-38700 is a low-severity information disclosure vulnerability affecting matrix-appservice-irc, a Node.js IRC bridge for Matrix, prior to version 1.0.1. An attacker could craft an event to leak partial message content from another bridged room if they knew a targeted event ID. The CVSS score is 3.7 (LOW) due to its limited impact (partial confidentiality loss) and high attack complexity, requiring specific knowledge. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this vulnerability.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.0.1CPE matchmatch criteria
cpe:2.3:a:matrix:matrix_irc_bridge:*:*:*:*:*:node.js:*:*

CVSS Data

CVSS version used by this source: 3.1

3.5LOW

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
1.8
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.48%
Probability of exploitation in next 30 days
EPSS Percentile
39.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0049 is in the 25th percentile among its peer group of 1,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

github_advisorypatch availablevia nvd_reference
View patch
harborpatch availablevia llm_extracted
Fixed in: matrix-appservice-irc 1.0.1, matrix-hookshot 4.4.1, matrix-appservice-slack 2.1.2, matrix-appservice-bridge 9.0.1 (and 8.1.2)
View patch
netgearpatch availablevia llm_extracted
Fixed in: matrix-appservice-irc 1.0.1
View patch
npmpatch availablevia ghsa
Product: matrix-appservice-ircFixed in: 1.0.1
phoenix_contactpatch availablevia llm_extracted
Fixed in: matrix-appservice-irc 1.0.1, matrix-hookshot 4.4.1, matrix-appservice-slack 2.1.2, matrix-appservice-bridge 9.0.1 (and 8.1.2)
View patch

Vendor Advisories (4)

npmGHSA-c7hh-3v6c-fj4qlow

matrix-appservice-irc events can be crafted to leak parts of targeted messages from other bridged rooms

Aug 4, 2023
netgearllm-netgear-dfbb5f084083b69aHIGH

Events can be crafted to leak parts of targeted messages from other bridged rooms

Jul 26, 2023
harborllm-harbor-1670ef3d989ba299HIGH

Multiple High Severity Vulnerabilities in Matrix Bridges

Jul 12, 2023
phoenix_contactllm-phoenix_contact-c12d9603f79c2712HIGH

Security Updates for Matrix Bridges: OpenID Token Exchange, IRC Command Injection, and Message Leak Vulnerabilities

Jul 10, 2023

References

github.com / matrix-org/matrix-appservice-irc/commit/8bbd2b69a16cbcbeffdd9b5c973fd89d61498d75
Patch
github.com / matrix-org/matrix-appservice-irc/releases/tag/1.0.1
Release Notes
github.com / matrix-org/matrix-appservice-irc/security/advisories/GHSA-c7hh-3v6c-fj4q
Vendor Advisory