Moderation Tool Vulnerability in Mjolnir by Matrix
CVE-2025-24024
9.1CRITICAL
What is CVE-2025-24024?
Mjolnir, a moderation tool for the Matrix communication platform, has a vulnerability that allows unauthorized users to execute management commands from any room where the bot is present. This poses significant risks, particularly if server administration features are enabled. Effective versions that address this issue include v1.9.1, which reverses the problematic feature, and v1.9.2, which safely reintroduces the necessary functionalities. Users unable to upgrade to these versions are advised to downgrade to v1.8.3 to mitigate potential exploits.
Affected Version(s)
mjolnir = 1.9.0