CVE-2023-43656 is a critical vulnerability affecting matrix-hookshot, a bot connecting Matrix to external services, specifically when transformation functions are enabled. This flaw allows attackers to escape the vm2 sandbox, potentially leading to full system compromise with a CVSS score of 9.0. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion, indicating awareness among security researchers. Users are advised to upgrade to version 4.5.0 or later, or disable generic.allowJsTransformationFunctions if an upgrade is not immediately possible.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.5.0CPE matchmatch criteria | cpe:2.3:a:matrix:hookshot:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.4 Reddit, 1.2 Bluesky, 0.9 Mastodon, and 2.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.8 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.