Matrix SDK Vulnerability in Rust Implementation Affects Data Integrity
CVE-2025-48937
4.9MEDIUM
What is CVE-2025-48937?
The matrix-sdk-crypto library in the Rust implementation of the Matrix client-server architecture contains a flaw that fails to properly validate the sender of encrypted events. This oversight permits malicious actors operating a homeserver to alter events transmitted to clients, leading to potential misrepresentation of messages as being sent by different users. Users receiving these altered events may be misled about the origin of the messages, thereby undermining the integrity of communication within the application. Resolved versions 0.11.1 and 0.12.0 mitigate this risk.
Affected Version(s)
matrix-rust-sdk >= 0.8.0, < 0.11.1