{"id":"GHSA-52rh-5rpj-c3w6","summary":"Improper handling of multiline messages in node-irc","details":"node-irc is a socket wrapper for the IRC protocol that extends Node.js' EventEmitter. The vulnerability allows an attacker to manipulate a Matrix user into executing IRC commands by having them reply to a maliciously crafted message. Incorrect handling of a CR character allowed for making part of the message be sent to the IRC server verbatim rather than as a message to the channel.\nThe vulnerability has been patched in node-irc version 1.2.1.","modified":"2026-02-11T22:03:06.197377Z","published":"2022-05-05T16:00:50Z","database_specific":{"github_reviewed_at":"2022-05-05T16:00:50Z","nvd_published_at":null,"cwe_ids":["CWE-74","CWE-93"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/matrix-org/node-irc/security/advisories/GHSA-52rh-5rpj-c3w6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-29166"},{"type":"WEB","url":"https://github.com/matrix-org/node-irc/commit/2976c856df37660a9d664e94c857c796de2e34f7"},{"type":"WEB","url":"https://github.com/matrix-org/node-irc/commit/e3eb9c15f8240e9c92365f5ffc3944469229771b"},{"type":"PACKAGE","url":"https://github.com/matrix-org/node-irc"},{"type":"WEB","url":"https://matrix.org/blog/2022/05/04/0-34-0-security-release-for-matrix-appservice-irc-high-severity"}],"affected":[{"package":{"name":"matrix-org-irc","ecosystem":"npm","purl":"pkg:npm/matrix-org-irc"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.2.1"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.2.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-52rh-5rpj-c3w6/GHSA-52rh-5rpj-c3w6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"}]}