CVE-2025-24024CWE-671

Mjolnir v1.9.0 accepts commands from any room

Critical · published January 21, 2025

CVSS v3.1
9.1
EPSS
1%
Percentile
46.3
In the wild
Unconfirmed
What it is

🚨 A moderation bot can be tricked into obeying anyone in its chat room! Mjolnir v1.9.0 has a vulnerability that allows unauthorized users to wield its powers — that’s a recipe for chaos! 🔥 Think of Mjolnir like a restaurant kitchen. If the chef leaves the door unlocked, anyone can waltz in and start cooking without a reservation — they could ruin a whole dinner service! An attacker could potentially execute server management commands, accessing sensitive moderation features and causing absolute havoc in the chat rooms. Imagine a rowdy group overtaking the head chef's authority and throwing a wild party in the kitchen — it could lead to data leaks, user harassment, or even server downtime!

Put simply

Think of Mjolnir like a restaurant kitchen. If the chef leaves the door unlocked, anyone can waltz in and start cooking without a reservation — they could ruin a whole dinner service! This vulnerability arises because Mjolnir v1.9.0 responds to management commands without verifying the sender’s authority, allowing non-operators to misuse its functionalities.

What to do

An attacker could potentially execute server management commands, accessing sensitive moderation features and causing absolute havoc in the chat rooms. Imagine a rowdy group overtaking the head chef's authority and throwing a wild party in the kitchen — it could lead to data leaks, user harassment, or even server downtime! Immediate action is essential! Upgrade to Mjolnir version 1.9.1 to close this security gap. If that's not feasible, downgrade to version 1.8.3 while you strategize your upgrade. Don’t leave your chat rooms vulnerable! You’ve got this! By following these steps, you can secure your chat environment in no time. 🛡️

The record
Technical detail
CVSS v3.1
9.1 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00595 · 46.3th percentile
Weakness
CWE-671 · Lack of Administrator Control over Security
Published
2025-01-21T19:21Z
EPSS history
Timeline
  • 21 JAN 19:21Z
    Mjolnir v1.9.0 accepts commands from any room
    cvelistv5