Impact
matrix-sdk-crypto, a component of the matrix‑org matrix-rust‑sdk project, handles end-to-end encryption for Matrix clients without performing network I/O. Beginning with version 0.12.0 and continuing through 0.16.x, the crate omitted a check for the user identifier when decrypting Olm-encrypted events that include a sender_device_keys field. This missing check is a CWE-290 flaw that allows an attacker who can collude with the homeserver operator to forge an encrypted to-device event that appears to come from a legitimate user. Although the flaw does not directly enable code execution or data exfiltration, it can mislead a client into attributing a message or policy update to an unrelated user, potentially undermining trust and session integrity.
Affected Systems
The affected product is the matrix‑sdk‑crypto component of matrix‑rust‑sdk from matrix‑org. Versions 0.12.0 through 0.16.x are vulnerable. Updates starting with version 0.17.0 include the missing check and are considered safe.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. The EPSS score is less than 1 % and the vulnerability is not listed in that widespread exploitation is unlikely. However, an attacker would need to collude with a homeserver operator to inject or alter the sender_device_keys during decryption, so the threat is concentrated on privileged or internal actors that can manipulate the homeserver environment.
OpenCVE Enrichment
Github GHSA