Junglewise Threat Intelligence

CVE-2024-53863: PYSEC-2026-1615 - Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders

CVE-2024-53863 · Severity: medium · CVSS 4 · Published 2026-07-07

Technologies: matrix-synapse (PyPI). Vendors: PyPI.

Executive brief

Synapse can be forced to thumbnail unexpected file formats, invoking external, potentially untrustworthy decoders

Affected products

  • PyPI matrix-synapse

Related threats