Logic Flaw in User Management Service for Matrix Homeservers by Element
CVE-2025-62425
What is CVE-2025-62425?
The Matrix Authentication Service, developed by Element, contains a logic flaw that can be exploited by users with authenticated sessions, allowing them to execute critical operations without re-entering their current password. This includes altering the password, modifying associated email addresses, and deactivating their own account. The issue arises specifically in configurations that enable the local password database feature, underscoring the importance of addressing this vulnerability through timely updates and configuration management.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
matrix-authentication-service >= 0.20.0, <= 1.4.0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
