Insufficient Validation in Element Web Client Allows Room List Manipulation
CVE-2025-59161
What is CVE-2025-59161?
Element Web, constructed with the Matrix React SDK, has a vulnerability that permits a remote attacker to temporarily manipulate the room list by replacing a room's entry with a different, attacker-supplied room. This flaw arises from inadequate validation of room predecessor links, potentially leading users to interact with the wrong room—an action that can confuse users who may act on false premises. Although this issue is temporary and can be resolved by refreshing the room list, it emphasizes the need for users to upgrade to version 1.11.112 to protect against such manipulation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
element-web < 1.11.112
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
