CVE-2025-48937: medium-severity vulnerability in matrix-org matrix-rust-sdk
matrix-sdk-crypto vulnerable to sender of encrypted events being spoofed by homeserver administrator
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 4.9epss 0.4%
exploitation probability
0.4%top 71% of all CVEs
observed exploitation
nono source reports it
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. matrix-sdk-crypto since version 0.8.0 and up to 0.11.0 does not correctly validate the sender of an encrypted event. Accordingly, a malicious homeserver operator can modify events served to clients, making those events appear to the recipient as if they were sent by another user. This vulnerability is fixed in 0.11.1 and 0.12.0.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
Affected products
matrix-org · matrix-rust-sdkRelated CVEs — matrix-org matrix-rust-sdk
In the same product, most dangerous first.
CVE-2022-39252HIGHWhen matrix-rust-sdk recieves forwarded room keys, the reciever doesn't check if it requested the key from the forwarderEPSS 0.6%CVE-2024-52813MEDIUMmatrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identityEPSS 0.5%CVE-2025-66622LOWmatrix-sdk-base is vulnerable to DoS via custom m.room.join_rules event valuesEPSS 0.4%CVE-2025-59047LOWmatrix-sdk-base has panic in the `RoomMember::normalized_power_level()` methodEPSS 0.4%CVE-2026-45056MEDIUMMatrix Rust SDK: Sender-binding gaps in to-device and room-key attributionEPSS 0.3%CVE-2025-53549MEDIUMMatrix Rust SDK allows SQL injection in the EventCache implementationEPSS 0.3%
References
https://github.com/matrix-org/matrix-rust-sdk/commit/13c1d2048286bbabf5e7bc6b015aafee98f04d55https://github.com/matrix-org/matrix-rust-sdk/commit/56980745b4f27f7dc72ac296e6aa003e5d92a75bhttps://github.com/matrix-org/matrix-rust-sdk/security/advisories/GHSA-x958-rvg6-956whttps://spec.matrix.org/v1.14/client-server-api/#mmegolmv1aes-sha2