Unknown · Matrix-Appservice-Irc · CVE-2025-27146
**Name of the Vulnerable Software and Affected Versions**
matrix-appservice-irc versions prior to 3.0.4
**Description**
The issue affects the matrix-appservice-irc bridge, allowing for arbitrary IRC command execution as the puppeted user. However, the attacker can only inject commands executed as their own IRC user.
**Recommendations**
For versions prior to 3.0.4, update to version 3.0.4 to resolve the issue.