Skip to content

User content sandbox can be confused into opening arbitrary documents and exposing user data

Moderate
jryans published GHSA-52mq-6jcv-j79x Mar 1, 2021

Package

npm matrix-react-sdk (npm)

Affected versions

< 3.15.0

Patched versions

>= 3.15.0

Description

Impact

The user content sandbox can be abused to trick users into opening unexpected documents after several user interactions. The content can be opened with a blob origin from the Matrix client, so it is possible for a malicious document to access user messages and secrets.

Patches

This has been fixed by #5657, which is included in 3.15.0.

Workarounds

There are no known workarounds.

Severity

Moderate

CVE ID

CVE-2021-21320

Weaknesses

No CWEs

Credits