Executive brief
The matrix-appservice-irc bridge, which connects Matrix chat rooms to IRC networks, contains a vulnerability that allows users to inject unauthorized IRC commands. By including newline characters in specific inputs like channel names, an attacker can trick the bridge bot into executing unintended administrative actions. This could lead to unauthorized channel management or manipulation of the IRC bridge's behavior.
Technical details
A command injection vulnerability exists in matrix-appservice-irc due to improper input validation of newline characters in administrative commands and channel names. An attacker can craft a string containing newlines that, when processed by the bridge, is interpreted as multiple separate IRC commands. This allows the attacker to bypass intended command parsing logic and execute arbitrary IRC commands as the bridge bot. The vulnerability is rooted in the command parser for admin and room commands. It is fixed in version 1.0.1 by refactoring the command parser to correctly trim and validate inputs.
Affected products
- Matrix.org matrix-appservice-irc < 1.0.1
Timeline
- 2023-07-31: patched: Version 1.0.1 released with security fixes.
- 2023-08-04: disclosed: Security advisory published.
References
- https://github.com/matrix-org/matrix-appservice-irc/security/advisories/GHSA-3pmj-jqqp-2mj3
- https://github.com/matrix-org/matrix-appservice-irc/commit/0afb064635d37e039067b5b3d6423448b93026d3
- https://github.com/matrix-org/matrix-appservice-irc
- https://github.com/matrix-org/matrix-appservice-irc/releases/tag/1.0.1