Logic Flaw in User Management Service for Matrix Homeservers by Element
CVE-2025-62425

8.3HIGH

Key Information:

Vendor

Element-hq

Vendor
CVE Published:
16 October 2025

What is CVE-2025-62425?

The Matrix Authentication Service, developed by Element, contains a logic flaw that can be exploited by users with authenticated sessions, allowing them to execute critical operations without re-entering their current password. This includes altering the password, modifying associated email addresses, and deactivating their own account. The issue arises specifically in configurations that enable the local password database feature, underscoring the importance of addressing this vulnerability through timely updates and configuration management.

Affected Version(s)

matrix-authentication-service >= 0.20.0, <= 1.4.0

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-62425 : Logic Flaw in User Management Service for Matrix Homeservers by Element