CVE 2.7 LOW

In Element Web and Element Desktop, a malicious room can hide an unrelated room and cause it to be left when the malicious room is left_CVE-2025-59161

2.7 / 10
LOW
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:U

Description

Element Web is a Matrix web client built using the Matrix React SDK. Element Web and Element Desktop before version 1.11.112 have insufficient validation of room predecessor links, allowing a remote attacker to attempt to impermanently replace a room's entry in the room list with an unrelated attacker-supplied room. While the effect of this is temporary, it may still confuse users into acting on incorrect assumptions. The issue has been patched and users should upgrade to 1.11.112. A reload/refresh will fix the incorrect room list state, removing the attacker's room and restoring the original room.

Basic Information

ID CVE-2025-59161
Source GitHub_M
Published Sep 16, 2025 at 16:44

Affected Product

Vendor element-hq
Product element-web
Version < 1.11.112
Affected Versions element-hq element-web < 1.11.112

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.