Prototype pollution in matrix-react-sdk
CVE-2022-36060
8.2HIGH
What is CVE-2022-36060?
The matrix-react-sdk, part of the Matrix chat protocol for React JavaScript, has a vulnerability that allows specially crafted string events to disrupt its functionality. This can lead to crashes of room or event tiles, impairing the user experience by preventing specific rooms or events from rendering, while other parts of the application may still appear operational. It is crucial for users to upgrade to version 3.53.0, as there are no effective workarounds available for this issue.
Affected Version(s)
matrix-react-sdk < 3.53.0