Executive brief
Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders
Affected products
- PyPI matrix-synapse
Junglewise Threat Intelligence
CVE-2024-53863 · Severity: medium · CVSS 4 · Published 2026-07-07
Technologies: matrix-synapse (PyPI). Vendors: PyPI.
Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders