Skip to main content

External Control of Critical State Data

CVE-2025-49090

Severity High
Score 7.1/10

Summary

The Matrix specification prior to 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state resolution.

  • HIGH
  • NETWORK
  • HIGH
  • CHANGED
  • NONE
  • LOW
  • NONE
  • LOW

CWE-642 - External Control of Critical State Data

The software stores security-critical state information about its users, or the software itself, in a location that is accessible to unauthorized actors.

Advisory Timeline

  • Published