Junglewise Threat Intelligence

CVE-2023-30609: Matrix React SDK HTML injection in search results

CVE-2023-30609 · Severity: low · CVSS 3.1 · Published 2023-04-25

Technologies: matrix-react-sdk (npm), Matrix.org React SDK. Vendors: npm, Matrix.org.

Executive brief

Matrix React SDK is a JavaScript library that powers Matrix chat client interfaces. When users search for messages, plaintext messages containing HTML tags are incorrectly rendered as active HTML in the search results, allowing attackers to inject malicious scripts. An attacker can trick a user into searching for a specially crafted message to execute cross-site scripting (XSS) attacks and steal data or compromise the user's account.

Technical details

The vulnerability is an HTML injection / cross-site scripting (CWE-74, CWE-79) in the search results display logic. When rendering search results, the SDK fails to properly sanitize or escape HTML entities in plaintext messages, causing HTML tags to be interpreted as markup rather than literal text. The attack requires authentication (PR:L) and user interaction (UI:R) to lure a victim into searching for the payload. However, the scope changes (S:C), affecting resources outside the search component. An attacker can inject resources from recaptcha.net and gstatic.com (domains whitelisted in the default CSP) to perform stored XSS. The issue is fixed in version 3.71.0; users can temporarily work around it by restarting the client.

Affected products

  • Matrix.org React SDK <= 3.70.0

Timeline

  • 2023-04-25: disclosed
  • 2023-04-25: patched: Version 3.71.0 released

References

Related threats