{"id":"GHSA-52rh-5rpj-c3w6","aliases":[],"url":"https://o3.security/vulnerability/GHSA-52rh-5rpj-c3w6","summary":"Improper handling of multiline messages in node-irc","details":"node-irc is a socket wrapper for the IRC protocol that extends Node.js' EventEmitter. The vulnerability allows an attacker to manipulate a Matrix user into executing IRC commands by having them reply to a maliciously crafted message. Incorrect handling of a CR character allowed for making part of the message be sent to the IRC server verbatim rather than as a message to the channel.\nThe vulnerability has been patched in node-irc version 1.2.1.","published":"2022-05-05T16:00:50Z","modified":"2026-02-11T22:03:06.197377Z","cvss":{"score":8,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"matrix-org-irc","fixedVersion":"1.2.1"}],"fix":{"url":"https://github.com/matrix-org/node-irc/commit/2976c856df37660a9d664e94c857c796de2e34f7","label":"matrix-org/node-irc@2976c85"},"references":[{"type":"WEB","url":"https://github.com/matrix-org/node-irc/security/advisories/GHSA-52rh-5rpj-c3w6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-29166"},{"type":"WEB","url":"https://github.com/matrix-org/node-irc/commit/2976c856df37660a9d664e94c857c796de2e34f7"},{"type":"WEB","url":"https://github.com/matrix-org/node-irc/commit/e3eb9c15f8240e9c92365f5ffc3944469229771b"},{"type":"PACKAGE","url":"https://github.com/matrix-org/node-irc"},{"type":"WEB","url":"https://matrix.org/blog/2022/05/04/0-34-0-security-release-for-matrix-appservice-irc-high-severity"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-11T22:03:06.197377Z"}}