CVE-2025-54315: High severity matrix Matrix specification vulnerability
Published Oct 2, 2025
·Updated
The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event uniqueness.
Affected Software
1 affected component
matrix Matrix specification<1.16
Event History
Oct 2, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-54315?
CVE-2025-54315 is considered a medium severity vulnerability due to its potential impact on event uniqueness in the Matrix protocol.
2
How do I fix CVE-2025-54315?
To fix CVE-2025-54315, upgrade your Matrix specification to version 1.16 or later.
3
What does CVE-2025-54315 affect?
CVE-2025-54315 affects the Matrix specification prior to version 1.16, specifically impacting room versioning.
4
What are the implications of CVE-2025-54315?
The implications of CVE-2025-54315 include potential issues with event handling and uniqueness in Matrix rooms, which could lead to data integrity problems.
5
When was CVE-2025-54315 disclosed?
CVE-2025-54315 was disclosed in 2025 as part of ongoing improvements to the Matrix protocol.