CVE-2025-24024
CVSS 3.1 Score 9.1 of 10 (high)
Details
Summary
CVE-2025-24024 is a vulnerability affecting Mjolnir, a moderation tool for the Matrix messaging platform. In its version 1.9.0, Mjolnir mistakenly grants management command responses to users who aren't bot operators, even in rooms where the bot isn't an administrator. This issue can potentially allow unauthorized users to utilize the bot's functions, including server administration components if enabled. The recommended solution is to downgrade to version 1.8.3, or upgrade to version 1.9.1 or higher and ensure the implementation of the safer reintroduced feature.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Mjolnir