Matrix Media Repo (MMR) is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions.
This is fixed in MMR v1.3.8.
Restricting which hosts MMR is allowed to contact via (local) firewall rules or a transparent proxy.
https://owasp.org/www-community/attacks/ServerSideRequestForgery https://learn.snyk.io/lesson/ssrf-server-side-request-forgery/ https://www.agwa.name/blog/post/preventingserversiderequestforgeryin_golang
{
"github_reviewed_at": "2025-01-16T19:35:02Z",
"cwe_ids": [
"CWE-918"
],
"github_reviewed": true,
"nvd_published_at": "2025-01-16T20:15:32Z",
"severity": "MODERATE"
}