trix
52 known vulnerabilities · 0 critical · 9 high
Trix has a stored XSS vulnerability through its attachment attribute
Trix has a cross-site Scripting vulnerability on copy & paste
Trix has a Stored XSS vulnerability through serialized attributes
Trix is vulnerable to XSS through JSON deserialization bypass in drag-and-drop (Level0InputController)
Parsing issue in matrix-org/node-irc leading to room takeovers
Improper beacon events in matrix-js-sdk can result in availability issues
OpenClaw: Matrix profile config persistence was reachable from operator.write message tools
matrix-js-sdk can be tricked into disclosing E2EE room keys to a participating homeserver
OpenClaw has a Matrix allowlist bypass via displayName and cross-homeserver localpart matching
OpenClaw: Matrix Verification Notices Bypass Matrix DM Policy and Reply to Unpaired DM Peers
Malicious code in orchestrix (npm)
matrix-js-sdk will freeze when a user sets a room with itself as a its predecessor
matrix-js-sdk subject to user impersonation due to key/device identifier confusion in SAS verification
Malicious code in atrix-mongoose (npm)
matrix-appservice-irc vulnerable to IRC mode parameter confusion
matrix-appservice-irc events can be crafted to leak parts of targeted messages from other bridged rooms
Matrix JavaScript SDK's key history sharing could share keys to malicious devices
matrix-js-sdk vulnerable to invisible eavesdropping in group calls
Malicious code in @trigo/atrix-swagger (npm)
Malicious code in @trigo/atrix-soap (npm)
Malicious code in matrix-charts (npm)
Malicious code in symphony-binary-confusion-matrix (npm)
Improper handling of multiline messages in node-irc affects matrix-appservice-irc
Malicious code in citrix-translate (npm)
Malicious code in citrixdeveloper-vscode (npm)
Malicious code in connectrix (npm)
Malicious code in com.citrix.cordova.testapp (npm)
Malicious code in testmatrix (npm)
Malicious code in @trigo/atrix-postgres (npm)
Malicious code in new-route-matrix (npm)
matrix-js-sdk subject to impersonated messages due to permissive key forwarding
Matrix-appservice-irc vulnerable to sql injection via roomIds argument
Malicious code in atrix (npm)
matrix-js-sdk subject to user spoofing via Olm/Megolm protocol confusion
matrix-appservice-bridge doesn't verify the sub parameter of an openId token exhange, allowing unauthorized access to provisioning APIs
Malicious code in @dentrix/fetlife-assets (npm)
Malicious code in @trigo/atrix-elasticsearch (npm)
Malicious code in @trigo/atrix-pubsub (npm)
Malicious code in @trigo/atrix (npm)
Malicious code in @trigo/atrix-acl (npm)
Malicious code in @trigo/atrix-mongoose (npm)
Malicious code in @trigo/atrix-orientdb (npm)
OpenClaw: Matrix thread root and reply context bypass sender allowlist
Malicious code in @aviatrixdev/flight-suit (npm)
Malicious code in @trigo/atrix-redis (npm)