Description
matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matrix-sdk-ui` crate prior to 0.17.0 is missing a check: when replacing an encrypted event, the replacement event itself is not required to be encrypted. This enables a malicious homeserver administrators (or actors with equivalent power) to impersonate or spoof messages as if they were sent by a victim user. `matrix-sdk-ui` 0.17.0 fixes the message edit validation logic to align with the algorithm for replacement events[^1] described in the Matrix specification. No known workarounds are available.
Published: 2026-09-11
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Message Spoofing
Action: Update
AI Analysis

Impact

matrix-sdk-ui provides GUI‑centric utilities on top of matrix‑rust‑sdk. The message edit validation logic in the `matrix-sdk-ui` crate prior to 0.17.0 is missing a check: when replacing an encrypted event, the replacement event itself is not required to be encrypted. This enables malicious homeserver administrators (or actors with equivalent power) to impersonate or spoof messages as if they were sent by a victim user. The flaw is classified as CWE‑345. The issue was fixed in release 0.17.0, which aligns the validation logic with the Matrix specification. No known workarounds are available.

Affected Systems

The Matrix SDK UI library from matrix-org, versions earlier than 0.17.0, is affected. Applications using these older releases with encrypted event editing enabled can be compromised by a homeserver administrator or an equivalent power holder.

Risk and Exploitability

The CVSS base score is 4.9, indicating a low‑to‑moderate severity. The EPSS score is less than 1 %, suggesting that exploitation is unlikely in the short term. The vulnerability is not listed in the CISA KEV catalog. The attack requires an adversary who already owns or can control the homeserver, as that authority is needed to introduce unencrypted replacement events, forging edits and spoofing victim messages. No public exploit has been disclosed.

Generated by OpenCVE AI on September 15, 2026 at 19:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade matrix-sdk-ui to 0.17.0 or later to apply the fixed edit validation logic
  • Ensure that your homeserver configuration enforces encryption for all replacement events and does not allow unencrypted edits from privileged actors, especially from users with elevated rights
  • Configure the homeserver to reject unencrypted replacement events, ensuring that only properly encrypted edits are accepted

Generated by OpenCVE AI on September 15, 2026 at 19:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-h97m-27fx-42rx matrix-sdk-ui: Incomplete edit validation
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Matrix-org
Matrix-org matrix-sdk-ui
Vendors & Products Matrix-org
Matrix-org matrix-sdk-ui

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Description matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matrix-sdk-ui` crate prior to 0.17.0 is missing a check: when replacing an encrypted event, the replacement event itself is not required to be encrypted. This enables a malicious homeserver administrators (or actors with equivalent power) to impersonate or spoof messages as if they were sent by a victim user. `matrix-sdk-ui` 0.17.0 fixes the message edit validation logic to align with the algorithm for replacement events[^1] described in the Matrix specification. No known workarounds are available.
Title matrix-sdk-ui: Incomplete edit validation
Weaknesses CWE-345
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N'}


Subscriptions

Matrix-org Matrix-sdk-ui
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T16:18:19.287Z

Reserved: 2026-05-08T18:07:27.342Z

Link: CVE-2026-45057

cve-icon Vulnrichment

Updated: 2026-09-14T16:16:20.530Z

cve-icon NVD

Status : Deferred

Published: 2026-09-11T21:17:09.517

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-45057

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T19:45:07Z

Weaknesses
  • CWE-345

    Insufficient Verification of Data Authenticity