{"id":"GHSA-xvg8-m4x3-w6xr","summary":"matrix-js-sdk has insufficient MXC URI validation which allows client-side path traversal","details":"### Summary\n\nmatrix-js-sdk before 34.11.0 is vulnerable to client-side path traversal via crafted MXC URIs. A malicious room member can trigger clients based on the matrix-js-sdk to issue arbitrary authenticated GET requests to the client's homeserver.\n\n### Details\n\nThe Matrix specification demands homeservers to [perform validation](https://spec.matrix.org/v1.12/client-server-api/#security-considerations-5) of the `server-name` and `media-id` components of MXC URIs with the intent to prevent path traversal. However, it is not mentioned that a similar check must also be performed on the client to prevent *client-side* path traversal. matrix-js-sdk fails to perform this validation.\n\n### Patches\n\nFixed in matrix-js-sdk 34.11.1.\n\n### Workarounds\n\nNone.\n\n### References\n\n- https://spec.matrix.org/v1.12/client-server-api/#security-considerations-5\n- https://blog.doyensec.com/2024/07/02/cspt2csrf.html","aliases":["CVE-2024-50336"],"modified":"2025-11-04T16:53:54Z","published":"2024-11-12T19:54:38Z","database_specific":{"nvd_published_at":"2024-11-12T17:15:09Z","cwe_ids":["CWE-22"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-11-12T19:54:38Z"},"references":[{"type":"WEB","url":"https://github.com/matrix-org/matrix-js-sdk/security/advisories/GHSA-xvg8-m4x3-w6xr"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-50336"},{"type":"PACKAGE","url":"https://github.com/matrix-org/matrix-js-sdk"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/01/msg00004.html"},{"type":"WEB","url":"https://spec.matrix.org/v1.12/client-server-api/#security-considerations-5"}],"affected":[{"package":{"name":"matrix-js-sdk","ecosystem":"npm","purl":"pkg:npm/matrix-js-sdk"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"34.11.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-xvg8-m4x3-w6xr/GHSA-xvg8-m4x3-w6xr.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N"}]}