Matrix SDK Vulnerability in Rust Implementation Affects Data Integrity
CVE-2025-48937
What is CVE-2025-48937?
The matrix-sdk-crypto library in the Rust implementation of the Matrix client-server architecture contains a flaw that fails to properly validate the sender of encrypted events. This oversight permits malicious actors operating a homeserver to alter events transmitted to clients, leading to potential misrepresentation of messages as being sent by different users. Users receiving these altered events may be misled about the origin of the messages, thereby undermining the integrity of communication within the application. Resolved versions 0.11.1 and 0.12.0 mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
matrix-rust-sdk >= 0.8.0, < 0.11.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
