Junglewise Threat Intelligence

CVE-2026-45057: matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matrix-sdk-ui` crate prio

CVE-2026-45057 · Severity: medium · CVSS 4.9 · Published 2026-09-11

Vendors: Matrix.org, crates.io.

Executive brief

A vulnerability in the Matrix Rust SDK's user interface library could allow a malicious server administrator to spoof messages. The software fails to ensure that edits to encrypted messages are also encrypted, allowing an attacker to replace legitimate secure communications with unencrypted fraudulent content. This could lead to impersonation of users within a Matrix-based chat application.

Technical details

The matrix-sdk-ui crate fails to properly validate replacement events (edits) for encrypted messages. Specifically, the logic does not enforce that a replacement event for an encrypted event must also be encrypted. A malicious homeserver administrator or an attacker with equivalent network privileges can exploit this by injecting unencrypted replacement events to impersonate users or spoof message content. This violates the Matrix specification regarding the validity of replacement events. The issue is fixed in version 0.16.1 by aligning the validation logic with the official Matrix algorithm.

Affected products

  • Matrix.org matrix-sdk-ui < 0.16.1

Timeline

  • 2026-04-17: patched: Pull request merged into main branch
  • 2026-05-08: advisory: Release 0.16.1 published
  • 2026-06-04: disclosed: Public security advisory published

References