{"id":"GHSA-cg57-p69r-3m7p","summary":"Improper file handling in matrix-react-sdk","details":"Matrix-React-SDK is a react-based SDK for inserting a Matrix chat/voip client into a web page. Before version 3.21.0, when uploading a file, the local file preview can lead to execution of scripts embedded in the uploaded file. This can only occur after several user interactions to open the preview in a separate tab. This only impacts the local user while in the process of uploading. It cannot be exploited remotely or by other users. This vulnerability is patched in version 3.21.0.","aliases":["CVE-2021-32622","GHSA-8796-gc9j-63rv"],"modified":"2026-07-08T06:49:32.495171089Z","published":"2022-02-10T23:46:51Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2021-05-19T17:48:44Z","nvd_published_at":"2021-05-17T20:15:00Z","cwe_ids":["CWE-434","CWE-74"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/matrix-org/matrix-react-sdk/security/advisories/GHSA-8796-gc9j-63rv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-32622"},{"type":"WEB","url":"https://github.com/matrix-org/matrix-react-sdk/pull/5981"},{"type":"WEB","url":"https://www.npmjs.com/package/matrix-react-sdk"}],"affected":[{"package":{"name":"matrix-react-sdk","ecosystem":"npm","purl":"pkg:npm/matrix-react-sdk"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.21.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/02/GHSA-cg57-p69r-3m7p/GHSA-cg57-p69r-3m7p.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L"}]}