Unknown · Matrix-Appservice-Irc · CVE-2023-38690
**Name of the Vulnerable Software and Affected Versions**
matrix-appservice-irc versions prior to 1.0.1
**Description**
The issue allows an attacker to craft a command with newlines that would not be properly parsed, enabling them to pass a string of commands as a channel name, which would then be executed by the IRC bridge bot.
**Recommendations**
For versions prior to 1.0.1, upgrade to version 1.0.1 or above to resolve the issue.
As a temporary workaround, consider disabling dynamic channels in the config to disable the most common execution method.