The Matrix React SDK Project maintains a focused client-side library for the Matrix communications protocol, widely embedded in web-based messaging and collaboration applications that rely on its authentication and message-handling implementation. The observed vulnerability surface reflects the web-application context of its deployments, centered on the SDK's role in client-side protocol integration. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Matrix React Sdk Project over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-28103HIGH matrix-react-sdk is a Matrix chat protocol SDK for React Javascript. In certain configurations, data sent by remote servers containing special strings in key locations could cause | Mar 28, 2023 | 8.2 | 25 | NO | NO |
CVE-2021-32622HIGH Matrix-React-SDK is a react-based SDK for inserting a Matrix chat/voip client into a web page. Before version 3.21.0, when uploading a file, the local file preview can lead to exec | May 17, 2021 | 7.8 | 24 | NO | NO |
CVE-2023-30609MEDIUM matrix-react-sdk is a react-based SDK for inserting a Matrix chat/VoIP client into a web page. Prior to version 3.71.0, plain text messages containing HTML tags are rendered as HTM | Apr 25, 2023 | 4.7 | 18 | NO | NO |
CVE-2023-37259MEDIUM matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. The Export Chat feature includes certain attacker-controlled elements in the generate | Jul 18, 2023 | 5.4 | 17 | NO | NO |
CVE-2021-21320MEDIUM matrix-react-sdk is an npm package which is a Matrix SDK for React Javascript. In matrix-react-sdk before version 3.15.0, the user content sandbox can be abused to trick users into | Mar 2, 2021 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Matrix React Sdk Project.
Media articles that mention a CVE ID that affects a product developed by Matrix React Sdk Project — matched by CVE ID, not by vendor name.