{"id":"CVE-2021-21320","aliases":["GHSA-52mq-6jcv-j79x"],"url":"https://o3.security/vulnerability/CVE-2021-21320","summary":"User content sandbox can be confused into opening arbitrary documents","details":"matrix-react-sdk is an npm package which is a Matrix SDK for React Javascript. In matrix-react-sdk before version 3.15.0, the user content sandbox can be abused to trick users into opening unexpected documents. The content is opened with a `blob` origin that cannot access Matrix user data, so messages and secrets are not at risk. This has been fixed in version 3.15.0.","published":"2021-03-02T03:15:13.213Z","modified":"2026-07-09T15:01:32.573480Z","cvss":{"score":4.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"matrix-react-sdk","fixedVersion":"3.15.0"}],"fix":{"url":"https://github.com/matrix-org/matrix-react-sdk/commit/b386f0c73b95ecbb6ea7f8f79c6ff5171a8dedd1","label":"matrix-org/matrix-react-sdk@b386f0c"},"references":[{"type":"ADVISORY","url":"https://github.com/matrix-org/matrix-react-sdk/security/advisories/GHSA-52mq-6jcv-j79x"},{"type":"ADVISORY","url":"https://www.npmjs.com/package/matrix-react-sdk"},{"type":"FIX","url":"https://github.com/matrix-org/matrix-react-sdk/commit/b386f0c73b95ecbb6ea7f8f79c6ff5171a8dedd1"},{"type":"FIX","url":"https://github.com/matrix-org/matrix-react-sdk/pull/5657"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T15:01:32.573480Z"}}