HTML Injection Vulnerability in Element Web by Element
CVE-2026-55850

5.3MEDIUM

Key Information:

Vendor

Element-hq

Vendor
CVE Published:
21 August 2026

What is CVE-2026-55850?

Element Web, a Matrix web client, has a security flaw that occurs when it renders homepage content from a homeserver using dangerouslySetInnerHTML. This method processes incoming HTML without appropriate sanitization, allowing a malicious homeserver to inject crafted HTML. Although the content security policy restricts JavaScript, it fails to mitigate risks from phishing attempts via malicious HTML. This issue has been addressed in version 1.12.22.

Affected Version(s)

element-web < 1.12.22

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.