CVE-2026-55850: Element Web: A malicious homeserver can inject HTML in Element Web using its homepage

Published Aug 21, 2026
·
Updated

Element Web is a Matrix web client built using the Matrix React SDK. Prior to 1.12.22, EmbeddedPage in apps/web/src/components/structures/EmbeddedPage.tsx renders homeserver-supplied homepage content through dangerouslySetInnerHTML without passing it through sanitizedHtmlNode. A malicious homeserver can provide crafted HTML that Element Web renders on the homepage; the content security policy prevents JavaScript but not phishing HTML. This issue is fixed in version 1.12.22.

Affected Software

1 affected component
Element Element Web<1.12.22

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Element Web to a version that resolves this vulnerability.

    Fixed in 1.12.22

Event History

Aug 21, 2026
CVE Published
via MITRE·06:30 PM
Data Sourced
via MITRE·06:30 PM
DescriptionWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Element Web users who connect to a malicious homeserver are exposed if they use a version earlier than 1.12.22. The homeserver can supply crafted homepage HTML that Element Web renders.

2

What does an attacker need to exploit it?

An attacker needs control of a homeserver that provides the homepage content. They can use crafted HTML for phishing; the content security policy prevents JavaScript execution.

3

Are users protected by default browser controls?

The described content security policy blocks JavaScript, but it does not prevent phishing HTML from being rendered. Users can therefore still be presented with deceptive homeserver-supplied content.

4

How can I remediate the issue?

Upgrade Element Web to version 1.12.22, which fixes the unsafe rendering path by sanitizing the homeserver-supplied homepage content.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203