Unknown · Matrix-Appservice-Irc · CVE-2022-3971
**Name of the Vulnerable Software and Affected Versions**
matrix-appservice-irc versions up to 0.35.1
**Description**
A critical issue affects the file src/datastore/postgres/PgDataStore.ts, where the manipulation of the `roomIds` argument leads to sql injection. Upgrading to version 0.36.0 addresses this issue.
**Recommendations**
For matrix-appservice-irc versions up to 0.35.1, upgrade to version 0.36.0 to address the issue. As a temporary workaround, consider restricting the manipulation of the `roomIds` argument to minimize the risk of sql injection.