CRITICAL🇵🇱 Wersja polska

CVE-2025-24024

CVSS 9.1v3.1pub. 2025-01-21upd. 2026-04-15

Mjolnir is a moderation tool for Matrix. Mjolnir v1.9.0 responds to management commands from any room the bot is member of. This can allow users who aren't operators of the bot to use the bot's functions, including server administration components if enabled. Version 1.9.1 reverts the feature that introduced the bug, and version 1.9.2 reintroduces the feature safely. Downgrading to version 1.8.3 is recommended if upgrading to 1.9.1 or higher isn't possible.

🤖 AI Analysis
How it works

In version 1.9.0, a feature was introduced that caused the Mjolnir bot to accept management commands from any Matrix room it belongs to, instead of only from the designated management room. An attacker who is a member of any room where the bot is present can issue it commands without having operator privileges. If server administration components are enabled, the scope of possible actions is particularly broad.

Impact

An unauthorized user can execute moderation and administrative bot functions, potentially compromising the integrity of the Matrix server and its configuration.

Mitigation & patch

Mjolnir should be updated to version 1.9.1 (which removes the vulnerable feature) or 1.9.2 (which reintroduces it in a secure manner). If updating to version 1.9.1 or later is not possible, it is recommended to revert to version 1.8.3.

Who is affected

Mjolnir version 1.9.0

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References