GHSA-f83w-wqhc-cfp4 · Severity: medium · Ecosystem: npm — Matrix SDK for React's URL preview setting for a room is controllable by the homeserver
matrix-react-sdk is a react-based SDK for inserting a Matrix chat/voip client into a web page. A malicious homeserver could manipulate a user's account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages would be sent to the server. This was patched in matrix-react-sdk 3.105.0. Deployments that trust their homeservers, as well as closed federations of trusted servers, are not affected. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Conclusion & alert: CVE-2024-42347 is rated Moderate Risk (56.5/100): CVSS High severity, with medium exploitation likelihood (EPSS 0.77%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-12-26 | 0.56% | 0.77% | +0.20% |
| 2 | 2025-11-21 | 0.27% | 0.56% | +0.29% |
| 3 | 2025-11-18 | — | 0.27% | — |
Full EPSS history (11 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.7 | 3.1 | HIGH |
|
3.1 | 4.0 | [email protected] |
| 6.5 | 3.1 | MEDIUM |
|
2.8 | 3.6 | [email protected] |
GHSA-f83w-wqhc-cfp4 · Severity: medium · Ecosystem: npm — Matrix SDK for React's URL preview setting for a room is controllable by the homeserver
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| matrix | matrix-react-sdk | < 3.105.1 | cpe:2.3:a:matrix:matrix-react-sdk:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/matrix-org/matrix-react-sdk/releases/tag/v3.105.1 | Release Notes |
| https://github.com/matrix-org/matrix-react-sdk/security/advisories/GHSA-f83w-wqhc-cfp4 | Vendor Advisory |