GHSA-52mq-6jcv-j79x

    Dashboard / Vulnerabilities / GHSA-52mq-6jcv-j79x

    GHSA-52mq-6jcv-j79x

    Published: 3 Mar 2021Last Modified: 8 Jul 2026

    Summary: User content sandbox can be confused into opening arbitrary documents

    Details: ### Impact The user content sandbox can be abused to trick users into opening unexpected documents after several user interactions. The content can be opened with a `blob` origin from the Matrix client, so it is possible for a malicious document to access user messages and secrets. ### Patches This has been fixed by https://github.com/matrix-org/matrix-react-sdk/pull/5657, which is included in 3.15.0. ### Workarounds There are no known workarounds.

    Affected packages

    Package

    Name: matrix-react-sdk

    Purl: pkg:npm/matrix-react-sdk

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -3.15.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-52mq-6jcv-j79x | CVE-DB