CVE-2022-36060: Prototype pollution in matrix-react-sdk
matrix-react-sdk is a Matrix chat protocol SDK for React Javascript. Events sent with special strings in key places can temporarily disrupt or impede the matrix-react-sdk from functioning properly, such as by causing room or event tile crashes. The remainder of the application can appear functional, though certain rooms/events will not be rendered. This issue has been fixed in matrix-react-sdk 3.53.0 and users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-36060?
CVE-2022-36060 is a vulnerability in the matrix-react-sdk library that can cause crashes or disruptions in the application.
What is the severity of CVE-2022-36060?
CVE-2022-36060 has a severity score of 5.3, which is considered high.
How does CVE-2022-36060 affect matrix-react-sdk?
CVE-2022-36060 can temporarily disrupt or impede the matrix-react-sdk, causing crashes or issues with room or event tiles.
What software versions are affected by CVE-2022-36060?
Versions of matrix-react-sdk up to and excluding 3.53.0 are affected by CVE-2022-36060.
How can I fix CVE-2022-36060?
To fix CVE-2022-36060, upgrade to a version of matrix-react-sdk that is beyond 3.53.0.