Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-59160

Опубликовано: 16 сент. 2025
Источник: nvd
EPSS Низкий

Описание

Matrix JavaScript SDK is a Matrix Client-Server SDK for JavaScript and TypeScript. matrix-js-sdk before 38.2.0 has insufficient validation of room predecessor links in MatrixClient::getJoinedRooms, allowing a remote attacker to attempt to replace a tombstoned room with an unrelated attacker-supplied room. The issue has been patched and users should upgrade to 38.2.0. A workaround is to avoid using MatrixClient::getJoinedRooms in favor of getRooms() and filtering upgraded rooms separately.

EPSS

Процентиль: 27%
0.00094
Низкий

Дефекты

CWE-345

Связанные уязвимости

ubuntu
5 месяцев назад

Matrix JavaScript SDK is a Matrix Client-Server SDK for JavaScript and TypeScript. matrix-js-sdk before 38.2.0 has insufficient validation of room predecessor links in MatrixClient::getJoinedRooms, allowing a remote attacker to attempt to replace a tombstoned room with an unrelated attacker-supplied room. The issue has been patched and users should upgrade to 38.2.0. A workaround is to avoid using MatrixClient::getJoinedRooms in favor of getRooms() and filtering upgraded rooms separately.

debian
5 месяцев назад

Matrix JavaScript SDK is a Matrix Client-Server SDK for JavaScript and ...

github
5 месяцев назад

matrix-js-sdk has insufficient validation when considering a room to be upgraded by another

EPSS

Процентиль: 27%
0.00094
Низкий

Дефекты

CWE-345