← Back to CVE List

CVE-2021-32622

Published: 2021-05-17T20:15Z
Last Modified: 2024-11-21T06:07Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Matrix-React-SDK is a react-based SDK for inserting a Matrix chat/voip client into a web page. Before version 3.21.0, when uploading a file, the local file preview can lead to execution of scripts embedded in the uploaded file. This can only occur after several user interactions to open the preview in a separate tab. This only impacts the local user while in the process of uploading. It cannot be exploited remotely or by other users. This vulnerability is patched in version 3.21.0. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt