Executive brief
matrix-react-sdk is a JavaScript library that powers the Element messaging client's web interface. The Export Chat feature allows users to download conversation history, but fails to properly escape attacker-controlled content, enabling stored cross-site scripting (XSS) attacks. A malicious Matrix server can inject malicious code into exported chats to potentially leak private message contents.
Technical details
The vulnerability is a stored XSS (CWE-79/80) in the Export Chat feature of matrix-react-sdk versions 3.32.0 through 3.75.x. The export function generates an HTML document but does not adequately escape attacker-controlled elements such as user display names or message content sourced from the Matrix homeserver. An attacker controlling a Matrix homeserver can inject arbitrary HTML/JavaScript into exported chat files. While the injected code runs in a sandboxed context (null origin), it can still be leveraged to exfiltrate message contents. The vulnerability requires user interaction (triggering the export function) and some level of privilege (malicious homeserver). This was patched in matrix-react-sdk 3.76.0.
Affected products
- Matrix.org matrix-react-sdk 3.32.0 to 3.75.x
Timeline
- 2023-07-18: disclosed
- 2023-07-18: patched: Fixed in matrix-react-sdk 3.76.0