Loading
matrix-appservice-irc is a Node.js IRC bridge for Matrix. The matrix-appservice-irc bridge up to version 3.0.3 contains a vulnerability which can lead to arbitrary IRC command execution as the puppeted user. The attacker can only inject commands executed as their own IRC user. The vulnerability has been patched in matrix-appservice-irc version 3.0.4.
Use CWE-77, Matrix vendor hub and Matrix Irc Bridge product page to widen CVE-2025-27146 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2022-39203, CVE-2022-29166 and CVE-2023-38690 for nearby disclosures in the same product family.