Skip to content

Improper handling of multiline messages in node-irc

High
dkasak published GHSA-52rh-5rpj-c3w6 May 4, 2022

Package

npm node-irc (npm)

Affected versions

<= 1.2.0

Patched versions

1.2.1

Description

Impact

The vulnerability allows an attacker to manipulate a Matrix user into executing IRC commands by having them reply to a maliciously crafted message.

Incorrect handling of a CR character allowed for making part of the message be sent to the IRC server verbatim rather than as a message to the channel.

Patches

The vulnerability has been patched in node-irc version 1.2.1.

References

Credits

Discovered by Val Lorentz.

For more information

If you have any questions or comments about this advisory, email us at security@matrix.org.

Severity

High

CVE ID

No known CVE

Weaknesses