Insufficient Validation in Element Web Client Allows Room List Manipulation
CVE-2025-59161
2.7LOW
What is CVE-2025-59161?
Element Web, constructed with the Matrix React SDK, has a vulnerability that permits a remote attacker to temporarily manipulate the room list by replacing a room's entry with a different, attacker-supplied room. This flaw arises from inadequate validation of room predecessor links, potentially leading users to interact with the wrong room—an action that can confuse users who may act on false premises. Although this issue is temporary and can be resolved by refreshing the room list, it emphasizes the need for users to upgrade to version 1.11.112 to protect against such manipulation.
Affected Version(s)
element-web < 1.11.112