CVE-2026-45057: CWE-345: Insufficient Verification of Data Authenticity in matrix-org matrix-sdk-ui
matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matrix-sdk-ui` crate prior to 0.17.0 is missing a check: when replacing an encrypted event, the replacement event itself is not required to be encrypted. This enables a malicious homeserver administrators (or actors with equivalent power) to impersonate or spoof messages as if they were sent by a victim user. `matrix-sdk-ui` 0.17.0 fixes the message edit validation logic to align with the algorithm for replacement events[^1] described in the Matrix specification. No known workarounds are available.
AI Analysis
Technical Summary
The matrix-sdk-ui crate before version 0.17.0 does not properly verify that replacement events for encrypted messages are themselves encrypted. This insufficient verification of data authenticity (CWE-345) enables attackers with homeserver administrative privileges to spoof or impersonate messages from other users by submitting unencrypted replacement events. The fix in 0.17.0 updates the message edit validation logic to conform to the Matrix protocol's algorithm for replacement events, preventing such spoofing.
Potential Impact
An attacker with homeserver administrator privileges or equivalent can impersonate or spoof messages as if sent by a victim user by exploiting the lack of encryption verification on replacement events. This compromises message integrity and authenticity but does not affect message confidentiality or availability. There are no known exploits in the wild.
Mitigation Recommendations
Upgrade matrix-sdk-ui to version 0.17.0 or later, which includes the official fix aligning message edit validation with the Matrix specification. No known workarounds are available.
CVE-2026-45057: CWE-345: Insufficient Verification of Data Authenticity in matrix-org matrix-sdk-ui
Description
matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matrix-sdk-ui` crate prior to 0.17.0 is missing a check: when replacing an encrypted event, the replacement event itself is not required to be encrypted. This enables a malicious homeserver administrators (or actors with equivalent power) to impersonate or spoof messages as if they were sent by a victim user. `matrix-sdk-ui` 0.17.0 fixes the message edit validation logic to align with the algorithm for replacement events[^1] described in the Matrix specification. No known workarounds are available.
CVSS v3.1
Score 4.9medium
Affected software
matrix-org
matrix-sdk-ui
pkg:cargo/matrix-org/matrix-sdk-uiRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The matrix-sdk-ui crate before version 0.17.0 does not properly verify that replacement events for encrypted messages are themselves encrypted. This insufficient verification of data authenticity (CWE-345) enables attackers with homeserver administrative privileges to spoof or impersonate messages from other users by submitting unencrypted replacement events. The fix in 0.17.0 updates the message edit validation logic to conform to the Matrix protocol's algorithm for replacement events, preventing such spoofing.
Potential Impact
An attacker with homeserver administrator privileges or equivalent can impersonate or spoof messages as if sent by a victim user by exploiting the lack of encryption verification on replacement events. This compromises message integrity and authenticity but does not affect message confidentiality or availability. There are no known exploits in the wild.
Mitigation Recommendations
Upgrade matrix-sdk-ui to version 0.17.0 or later, which includes the official fix aligning message edit validation with the Matrix specification. No known workarounds are available.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-08T18:07:27.342Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aa4701a91cc7f3848aa73e7
Added to database: 09/11/2026, 21:18:18 UTC
Last enriched: 09/11/2026, 21:32:42 UTC
Last updated: 09/11/2026, 22:23:23 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.