Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-45057— matrix-sdk-ui: Incomplete edit validation

Quick assessment

Affected
matrix-org matrix-sdk-ui
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 之上提供了以图形用户界面(GUI)为中心的工具集。在版本 0.17.0 之前, crate 中的消息编辑校验逻辑存在一个缺失的检查项:当替换一个加密事件时,被用来替换的“新事件”本身并未被要求必须是加密的。这一缺陷使得恶意的 homeserver 管理员(或拥有同等权限的角色)能够冒充或伪造消息,使其看起来像是由受害用户发送的。 0.17.0 版本修复了消息编辑的校验逻辑,使其与 Matrix 规范中关于替换事件[^1]的算法保持一致。目前尚未发现可用的变通方案。

CVSS 4.9 · Medium EPSS 0.02% · P5
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-45057

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
matrix-sdk-ui: Incomplete edit validation
Source: CVE Program / CVE List V5
Vulnerability Description
matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matrix-sdk-ui` crate prior to 0.17.0 is missing a check: when replacing an encrypted event, the replacement event itself is not required to be encrypted. This enables a malicious homeserver administrators (or actors with equivalent power) to impersonate or spoof messages as if they were sent by a victim user. `matrix-sdk-ui` 0.17.0 fixes the message edit validation logic to align with the algorithm for replacement events[^1] described in the Matrix specification. No known workarounds are available.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
对数据真实性的验证不充分
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
matrix-org matrix-sdk-ui < 0.16.1 -

II. Public POCs for CVE-2026-45057

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-45057

登录查看更多情报信息。

Patches & Fixes for CVE-2026-45057 (2)

Vendor Advisories for CVE-2026-45057 (2)

IV. Related Vulnerabilities

V. Comments for CVE-2026-45057

No comments yet


Leave a comment