Security: matrix-org/matrix-js-sdk
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Insufficient validation when considering a room to be upgraded by anotherGHSA-mp7c-m3rh-r56v published
Sep 16, 2025 by davidegirardiLow -
Insufficient MXC URI validation allows client-side path traversalGHSA-xvg8-m4x3-w6xr published
Nov 12, 2024 by davidegirardiModerate -
A room with itself as a its predecessor will freeze matrix-js-sdkGHSA-vhr5-g3pm-49fm published
Aug 20, 2024 by davidegirardiHigh -
Invisible eavesdropping in group callsGHSA-6g67-q39g-r79q published
Apr 13, 2023 by dkasakModerate -
Prototype pollution in matrix-js-sdk (part 2)GHSA-mwq8-fjpf-c2gr published
Mar 28, 2023 by dkasakHigh -
Impersonation via forwarded Megolm sessionsGHSA-6263-x97c-c4gg published
Sep 28, 2022 by dkasakModerate -
Improper beacon events can cause availability issuesGHSA-hvv8-5v86-r45x published
Sep 28, 2022 by turt2liveModerate -
Prototype pollution in matrix-js-sdkGHSA-rfv9-x7hh-xc32 published
Mar 28, 2023 by dkasakHigh -
Olm/Megolm protocol confusionGHSA-r48r-j8fx-mq2c published
Sep 28, 2022 by dkasakCritical -
Key/device identifier confusion in SAS verificationGHSA-5w8r-8pgj-5jmf published
Sep 29, 2022 by dkasakCritical