Impact
matrix-sdk-ui provides GUI‑centric utilities on top of matrix‑rust‑sdk. The message edit validation logic in the `matrix-sdk-ui` crate prior to 0.17.0 is missing a check: when replacing an encrypted event, the replacement event itself is not required to be encrypted. This enables malicious homeserver administrators (or actors with equivalent power) to impersonate or spoof messages as if they were sent by a victim user. The flaw is classified as CWE‑345. The issue was fixed in release 0.17.0, which aligns the validation logic with the Matrix specification. No known workarounds are available.
Affected Systems
The Matrix SDK UI library from matrix-org, versions earlier than 0.17.0, is affected. Applications using these older releases with encrypted event editing enabled can be compromised by a homeserver administrator or an equivalent power holder.
Risk and Exploitability
The CVSS base score is 4.9, indicating a low‑to‑moderate severity. The EPSS score is less than 1 %, suggesting that exploitation is unlikely in the short term. The vulnerability is not listed in the CISA KEV catalog. The attack requires an adversary who already owns or can control the homeserver, as that authority is needed to introduce unencrypted replacement events, forging edits and spoofing victim messages. No public exploit has been disclosed.
OpenCVE Enrichment
Github GHSA