Skip to main content

CVE-2026-45057: CWE-345: Insufficient Verification of Data Authenticity in matrix-org matrix-sdk-ui

0
Medium
VulnerabilityCVE-2026-45057cvecve-2026-45057cwe-345
Published: 09/11/2026 (09/11/2026, 21:12:17 UTC)
Source: CVE Database V5
Vendor/Project: matrix-org
Product: matrix-sdk-ui

Description

matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matrix-sdk-ui` crate prior to 0.17.0 is missing a check: when replacing an encrypted event, the replacement event itself is not required to be encrypted. This enables a malicious homeserver administrators (or actors with equivalent power) to impersonate or spoof messages as if they were sent by a victim user. `matrix-sdk-ui` 0.17.0 fixes the message edit validation logic to align with the algorithm for replacement events[^1] described in the Matrix specification. No known workarounds are available.

CVSS v3.1

Score 4.9medium

Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N

Affected software

matrix-org

matrix-sdk-ui

Affected versions
<0.16.1
crates.iomore threats →ai
matrix-org/matrix-sdk-ui
pkg:cargo/matrix-org/matrix-sdk-ui
Affected versions
<0.16.1

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/11/2026, 21:32:42 UTC

Technical Analysis

The matrix-sdk-ui crate before version 0.17.0 does not properly verify that replacement events for encrypted messages are themselves encrypted. This insufficient verification of data authenticity (CWE-345) enables attackers with homeserver administrative privileges to spoof or impersonate messages from other users by submitting unencrypted replacement events. The fix in 0.17.0 updates the message edit validation logic to conform to the Matrix protocol's algorithm for replacement events, preventing such spoofing.

Potential Impact

An attacker with homeserver administrator privileges or equivalent can impersonate or spoof messages as if sent by a victim user by exploiting the lack of encryption verification on replacement events. This compromises message integrity and authenticity but does not affect message confidentiality or availability. There are no known exploits in the wild.

Mitigation Recommendations

Upgrade matrix-sdk-ui to version 0.17.0 or later, which includes the official fix aligning message edit validation with the Matrix specification. No known workarounds are available.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
GitHub_M
Date Reserved
2026-05-08T18:07:27.342Z
Cvss Version
3.1
State
PUBLISHED

Threat ID: 6aa4701a91cc7f3848aa73e7

Added to database: 09/11/2026, 21:18:18 UTC

Last enriched: 09/11/2026, 21:32:42 UTC

Last updated: 09/11/2026, 22:23:23 UTC

Views: 3

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses