CVE-2024-42347: Matrix SDK for React's URL preview setting for a room is controllable by the HS
A malicious homeserver could manipulate a user’s account data to cause the client to enable URL previews in end-to-end encrypted rooms, in which case any URLs in encrypted messages would be sent to the server.
References
Detect and mitigate CVE-2024-42347 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →