CVE-2025-59161: In Element Web and Element Desktop, a malicious room can hide an unrelated room and cause it to be left when the malicious room is left
Element Web is a Matrix web client built using the Matrix React SDK. Element Web and Element Desktop before version 1.11.112 have insufficient validation of room predecessor links, allowing a remote attacker to attempt to impermanently replace a room's entry in the room list with an unrelated attacker-supplied room. While the effect of this is temporary, it may still confuse users into acting on incorrect assumptions. The issue has been patched and users should upgrade to 1.11.112. A reload/refresh will fix the incorrect room list state, removing the attacker's room and restoring the original room.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59161?
CVE-2025-59161 is considered a significant vulnerability due to its potential to allow remote attackers to manipulate room entries.
How do I fix CVE-2025-59161?
To fix CVE-2025-59161, update Element Web or Element Desktop to version 1.11.112 or higher.
What products are affected by CVE-2025-59161?
CVE-2025-59161 affects both Element Web and Element Desktop versions prior to 1.11.112.
What issue does CVE-2025-59161 cause in Element applications?
CVE-2025-59161 allows insufficient validation of room predecessor links, potentially enabling remote attacks.
Is there a workaround for CVE-2025-59161?
There is no official workaround for CVE-2025-59161; users are advised to update their software to mitigate the vulnerability.