{"id":"CVE-2021-21320","details":"matrix-react-sdk is an npm package which is a Matrix SDK for React Javascript. In matrix-react-sdk before version 3.15.0, the user content sandbox can be abused to trick users into opening unexpected documents. The content is opened with a `blob` origin that cannot access Matrix user data, so messages and secrets are not at risk. This has been fixed in version 3.15.0.","aliases":["GHSA-52mq-6jcv-j79x"],"modified":"2026-07-09T15:01:32.573480Z","published":"2021-03-02T03:15:13.213Z","references":[{"type":"ADVISORY","url":"https://github.com/matrix-org/matrix-react-sdk/security/advisories/GHSA-52mq-6jcv-j79x"},{"type":"ADVISORY","url":"https://www.npmjs.com/package/matrix-react-sdk"},{"type":"FIX","url":"https://github.com/matrix-org/matrix-react-sdk/commit/b386f0c73b95ecbb6ea7f8f79c6ff5171a8dedd1"},{"type":"FIX","url":"https://github.com/matrix-org/matrix-react-sdk/pull/5657"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/matrix-org/matrix-react-sdk","events":[{"introduced":"0"},{"fixed":"9ab92e7971ae830fe77cc12a0a249ee8794f456c"},{"fixed":"b386f0c73b95ecbb6ea7f8f79c6ff5171a8dedd1"}],"database_specific":{"cpe":"cpe:2.3:a:matrix-react-sdk_project:matrix-react-sdk:*:*:*:*:*:node.js:*:*","extracted_events":[{"introduced":"0"},{"fixed":"3.15.0"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v3.15.0-rc.1","v3.0.0","v2.2.2","v2.1.1","v1.7.2","v1.6.1","v0.12.6","v0.12.4","v0.12.6-rc.1","v0.12.5","v0.12.4-rc.6","v0.12.4-rc.5","v0.12.4-rc.4","v0.12.4-rc.3","v0.12.4-rc.2","v0.12.4-rc.1","v0.10.2","v0.9.1","v0.9.0","v0.9.0-rc.2","v0.8.6-rc.2","v0.8.6-rc.1","v0.8.3","v0.8.2","v0.8.0","v0.7.5-rc.1","v0.7.4","v0.7.3","v0.7.2","v0.7.0-rc2","v0.7.0-rc1","v0.6.5","v0.6.4-r1","v0.6.4","v0.6.3","v0.6.2","v0.6.1","v0.6.0","v0.5.2","v0.5.1","v0.5.0","v0.4.0","v0.3.1","v0.3.0","v0.2.0","v0.1.1","v0.0.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-21320.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"}]}