Junglewise Threat Intelligence

CVE-2025-27146: Matrix IRC Bridge command injection in puppeted user

CVE-2025-27146 · Severity: low · CVSS 3.1 · Published 2025-02-25

Technologies: Matrix-Appservice-Irc. Vendors: npm.

Executive brief

The Matrix IRC Bridge is a service that allows users to communicate between Matrix chat networks and IRC channels. A vulnerability allows authenticated users with elevated privileges to inject malicious IRC commands that execute as their own IRC user account, potentially disrupting IRC channel operations or manipulating messages. The impact is limited because attackers can only compromise their own IRC identity, not other users' accounts.

Technical details

The vulnerability is a command injection flaw (CWE-77, CWE-88) in matrix-appservice-irc versions before 3.0.4, located in BridgedClient.ts. The vulnerability occurs when the bridge constructs IRC commands without properly neutralizing special elements such as newline characters in user input. An attacker with high privileges can inject newline characters to break out of the intended command and execute arbitrary IRC commands as their own puppeted user. The attack requires network access and high-privilege authentication but no user interaction. The fix, implemented in version 3.0.4, replaces newline characters with pipe characters ("|") to match IRC conventions and prevent command injection.

Affected products

  • Matrix matrix-appservice-irc < 3.0.4

Timeline

  • 2025-02-25: disclosed
  • 2025-02-25: patched: Patch released in version 3.0.4

References

Related threats