CVE-2023-28427: high-severity vulnerability in matrix-org matrix-js-sdk
Prototype pollution in matrix-js-sdk
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
A flaw in matrix-js-sdk allows attackers to send specially crafted messages that corrupt or hide data in the application, even though it appears to be working normally. This can cause the app to silently process incorrect information, compromising data integrity.
Prototype pollution vulnerability in matrix-js-sdk versions before 24.0.0 allows remote attackers to inject malicious property names in Matrix protocol events, corrupting runtime object prototypes and causing data exclusion or modification. The attack requires sending crafted messages through the Matrix protocol; impact includes silent data corruption while the SDK appears functional.
In the same product, most dangerous first.