T2bot develops the Matrix Media Repo, a media storage and retrieval component for the Matrix protocol ecosystem, with observed vulnerabilities centered on resource management and input-handling weaknesses including resource-exhaustion conditions, untrusted deserialization, improper authentication, and server-side request forgery. These patterns reflect the attack surface inherent to a service that accepts and serves user-supplied media files within a federated communication network. Current vulnerability counts, severity, and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by T2bot over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-52791HIGH Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR makes requests to other servers as part of normal operation, and these resource o | Jan 16, 2025 | 7.5 | 20 | NO | NO |
CVE-2024-36403HIGH Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 is vulnerable to unbounded disk consumption, where an unauth | Jan 16, 2025 | 7.5 | 20 | NO | NO |
CVE-2024-56515MEDIUM Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. If SVG or JPEGXL thumbnailers are enabled (they are disabled by default), a user may | Jan 16, 2025 | 6.5 | 18 | NO | NO |
CVE-2024-52602MEDIUM Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. Matrix Media Repo (MMR) is vulnerable to server-side request forgery, serving content | Jan 16, 2025 | 5.3 | 17 | NO | NO |
CVE-2024-36402MEDIUM Matrix Media Repo (MMR) is a highly configurable multi-homeserver media repository for Matrix. MMR before version 1.3.5 allows, by design, unauthenticated remote participants to tr | Jan 16, 2025 | 5.3 | 16 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by T2bot.
Media articles that mention a CVE ID that affects a product developed by T2bot — matched by CVE ID, not by vendor name.