CVE-2025-27146
CVSS 3.1 Score 4.3 of 10 (medium)
Details
Published Feb 25, 2025
Updated: Mar 4, 2025
CWE ID 88
CWE ID 77
Summary
CVE-2025-27146 is a vulnerability affecting matrix-appservice-irc, a Node.js IRC bridge for Matrix. The issue, present in versions up to 3.0.3, allows an attacker to execute arbitrary IRC commands as the puppeted user. This vulnerability poses a threat as the attacker can only inject commands under their own IRC user. matrix-appservice-irc version 3.0.4 has been released to address this security concern.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Matrix Partners