PT-2024-35961 · Synapse+3 · Synapse+3

CVE-2024-53863

·

Published

2024-12-03

·

Updated

2026-07-07

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Synapse versions prior to 1.120.1
Description: Synapse is an open-source Matrix homeserver. Enabling the dynamic thumbnails option or processing a specially crafted request could trigger the decoding and thumbnail generation of uncommon image formats, potentially invoking external tools like Ghostscript for processing. This significantly expands the attack surface in a historically vulnerable area, presenting a risk that far outweighs the benefit, particularly since these formats are rarely used on the open web or within the Matrix ecosystem. The issue is addressed by restricting thumbnail generation to images in widely used formats: PNG, JPEG, GIF, and WebP.
Recommendations: For Synapse versions prior to 1.120.1, update to version 1.120.1 to restrict thumbnail generation to widely used image formats. As a temporary workaround, consider disabling the dynamic thumbnails option until a patch is available. Ensure any image codecs and helper programs, such as Ghostscript, are patched against security vulnerabilities. Uninstall unused image decoder libraries and helper programs, such as Ghostscript, from the system environment that Synapse is running in.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-53863
GHSA-VP6V-WHFM-RV3G
OPENSUSE-SU-2024:14541-1
PYSEC-2026-1615
USN-7444-1

Affected Products

Ghostscript
Linuxmint
Synapse
Ubuntu