GHSA-35g4-qx3c-vjhx

    Dashboard / Vulnerabilities / GHSA-35g4-qx3c-vjhx

    GHSA-35g4-qx3c-vjhx

    Published: 21 Jun 2021Last Modified: 8 Jul 2026

    Summary: Automatic room upgrade handling can be used maliciously to bridge a room non-consentually

    Details: ### Impact If a bridge has room upgrade handling turned on in the configuration (the `roomUpgradeOpts` key when instantiating a new `Bridge` instance.), any `m.room.tombstone` event it encounters will be used to unbridge the current room and bridge into the target room. However, the target room `m.room.create` event is not checked to verify if the `predecessor` field contains the previous room. This means that any mailcious admin of a bridged room can repoint the traffic to a different room without the new room being aware. ### Patches Versions 2.6.1 and greater are patched. ### Workarounds Disabling the automatic room upgrade handling can be done by removing the `roomUpgradeOpts` key from the `Bridge` class options. ### References The issue is patched by https://github.com/matrix-org/matrix-appservice-bridge/pull/330 ### For more information] If you have any questions or comments about this advisory, email us at [email protected].

    Affected packages

    Package

    Name: matrix-appservice-bridge

    Purl: pkg:npm/matrix-appservice-bridge

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -2.6.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-35g4-qx3c-vjhx | CVE-DB