Logic Flaw in User Management Service for Matrix Homeservers by Element
CVE-2025-62425
8.3HIGH
What is CVE-2025-62425?
The Matrix Authentication Service, developed by Element, contains a logic flaw that can be exploited by users with authenticated sessions, allowing them to execute critical operations without re-entering their current password. This includes altering the password, modifying associated email addresses, and deactivating their own account. The issue arises specifically in configurations that enable the local password database feature, underscoring the importance of addressing this vulnerability through timely updates and configuration management.
Affected Version(s)
matrix-authentication-service >= 0.20.0, <= 1.4.0