Matrix SDK Vulnerability in Rust Implementation Affects Data Integrity
CVE-2025-48937

4.9MEDIUM

Key Information:

Vendor

Matrix-org

Vendor
CVE Published:
10 June 2025

What is CVE-2025-48937?

The matrix-sdk-crypto library in the Rust implementation of the Matrix client-server architecture contains a flaw that fails to properly validate the sender of encrypted events. This oversight permits malicious actors operating a homeserver to alter events transmitted to clients, leading to potential misrepresentation of messages as being sent by different users. Users receiving these altered events may be misled about the origin of the messages, thereby undermining the integrity of communication within the application. Resolved versions 0.11.1 and 0.12.0 mitigate this risk.

Affected Version(s)

matrix-rust-sdk >= 0.8.0, < 0.11.1

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-48937 : Matrix SDK Vulnerability in Rust Implementation Affects Data Integrity