matrix-media-repo (MMR) allows unauthenticated writes to the media repository, which may allow planting of problematic content in github.com/t2bot/matrix-media-repo
{
"url": "https://pkg.go.dev/vuln/GO-2025-3397",
"review_status": "UNREVIEWED"
}