{"id":"CVE-2023-38700","aliases":["GHSA-c7hh-3v6c-fj4q"],"url":"https://o3.security/vulnerability/CVE-2023-38700","summary":"matrix-appservice-irc events can be crafted to leak parts of targeted messages from other bridged rooms","details":"matrix-appservice-irc is a Node.js IRC bridge for Matrix. Prior to version 1.0.1, it was possible to craft an event such that it would leak part of a targeted message event from another bridged room. This required knowing an event ID to target. Version 1.0.1n fixes this issue. As a workaround, set the `matrixHandler.eventCacheSize` config value to `0`. This workaround may impact performance.","published":"2023-08-04T18:05:43.187Z","modified":"2026-07-15T01:48:55.122992275Z","cvss":{"score":3.5,"severity":"LOW","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"matrix-appservice-irc","fixedVersion":"1.0.1"}],"fix":{"url":"https://github.com/matrix-org/matrix-appservice-irc/commit/8bbd2b69a16cbcbeffdd9b5c973fd89d61498d75","label":"matrix-org/matrix-appservice-irc@8bbd2b6"},"references":[{"type":"WEB","url":"https://github.com/matrix-org/matrix-appservice-irc/releases/tag/1.0.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/38xxx/CVE-2023-38700.json"},{"type":"ADVISORY","url":"https://github.com/matrix-org/matrix-appservice-irc/security/advisories/GHSA-c7hh-3v6c-fj4q"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-38700"},{"type":"FIX","url":"https://github.com/matrix-org/matrix-appservice-irc/commit/8bbd2b69a16cbcbeffdd9b5c973fd89d61498d75"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:55.122992275Z"}}