CVE-2024-51750: Element allows a malicious homeserver can modify events leading to unrenderable events or rooms
Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over federation which can prevent Element Web and Desktop from rendering single messages or the entire room containing them. This was patched in Element Web and Desktop 1.11.85.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-51750?
CVE-2024-51750 is classified as a medium severity vulnerability that affects Element Web and Element Desktop clients.
How do I fix CVE-2024-51750?
To fix CVE-2024-51750, users should upgrade to Element Web and Desktop versions 1.11.85 or later.
What impact does CVE-2024-51750 have on Element users?
CVE-2024-51750 can prevent Element Web and Desktop from rendering invalid messages, affecting communication in rooms.
Which versions of Element are affected by CVE-2024-51750?
CVE-2024-51750 affects Element Web and Desktop versions prior to 1.11.85.
Can CVE-2024-51750 allow for data leakage?
CVE-2024-51750 does not directly facilitate data leakage but can disrupt message rendering and user communication.