GHSA-6g67-q39g-r79q

    Dashboard / Vulnerabilities / GHSA-6g67-q39g-r79q

    GHSA-6g67-q39g-r79q

    Published: 14 Apr 2023Last Modified: 10 Sept 2026

    Summary: matrix-js-sdk vulnerable to invisible eavesdropping in group calls

    Details: ### Impact An attacker present in a room where an [MSC3401](https://github.com/matrix-org/matrix-spec-proposals/pull/3401) group call is taking place can eavesdrop on the video and audio of participants using matrix-js-sdk, without their knowledge. To affected matrix-js-sdk users, the attacker will not appear to be participating in the call. This attack is possible because matrix-js-sdk's group call implementation accepts incoming direct calls from other users, even if they have not yet declared intent to participate in the group call, as a means of resolving a race condition in call setup. Affected versions do not restrict access to the user's outbound media in this case. Legacy 1:1 calls are unaffected. ### Workarounds Users may hold group calls in private rooms where only the exact users who are expected to participate in the call are present.

    Affected packages

    Package

    Name: matrix-js-sdk

    Purl: pkg:npm/matrix-js-sdk

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -24.1.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-6g67-q39g-r79q | CVE-DB