External Control of Critical State Data
CVE-2025-49090
Summary
The Matrix specification prior to 1.16 (i.e., with a room version before 12 and State Resolution before 2.1) has deficient state resolution.
- HIGH
- NETWORK
- HIGH
- CHANGED
- NONE
- LOW
- NONE
- LOW
CWE-642 - External Control of Critical State Data
The software stores security-critical state information about its users, or the software itself, in a location that is accessible to unauthorized actors.
References
Advisory Timeline
- Published