CVE-2025-54315: High severity matrix Matrix specification vulnerability
The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event uniqueness.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Matrix specificationto a version that resolves this vulnerability.Fixed in 1.16
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54315?
CVE-2025-54315 is considered a medium severity vulnerability due to its potential impact on event uniqueness in the Matrix protocol.
How do I fix CVE-2025-54315?
To fix CVE-2025-54315, upgrade your Matrix specification to version 1.16 or later.
What does CVE-2025-54315 affect?
CVE-2025-54315 affects the Matrix specification prior to version 1.16, specifically impacting room versioning.
What are the implications of CVE-2025-54315?
The implications of CVE-2025-54315 include potential issues with event handling and uniqueness in Matrix rooms, which could lead to data integrity problems.
When was CVE-2025-54315 disclosed?
CVE-2025-54315 was disclosed in 2025 as part of ongoing improvements to the Matrix protocol.