HTML Injection Vulnerability in Element Web by Element
CVE-2026-55850
5.3MEDIUM
What is CVE-2026-55850?
Element Web, a Matrix web client, has a security flaw that occurs when it renders homepage content from a homeserver using dangerouslySetInnerHTML. This method processes incoming HTML without appropriate sanitization, allowing a malicious homeserver to inject crafted HTML. Although the content security policy restricts JavaScript, it fails to mitigate risks from phishing attempts via malicious HTML. This issue has been addressed in version 1.12.22.
Affected Version(s)
element-web < 1.12.22
