CVE-2025-59161 Details
Description
Element Web is a Matrix web client built using the Matrix React SDK. Element Web and Element Desktop before version 1.11.112 have insufficient validation of room predecessor links, allowing a remote attacker to attempt to impermanently replace a room's entry in the room list with an unrelated attacker-supplied room. While the effect of this is temporary, it may still confuse users into acting on incorrect assumptions. The issue has been patched and users should upgrade to 1.11.112. A reload/refresh will fix the incorrect room list state, removing the attacker's room and restoring the original room.
A vulnerability exists in Element Web and Element Desktop versions through 1.11.111, where there is inadequate validation of room predecessor links. This flaw allows remote attackers to temporarily replace a room's entry in the room list with an unrelated room of their choosing. Although this change is not permanent, it can mislead users into making incorrect assumptions.
Users are advised to upgrade to version 1.11.112. After updating, a simple reload or refresh will restore the correct room list state by removing the attacker's room and bringing back the original one.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 16, 2025CISA-ADP
Assessed Sep 16, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/element-hq/element-web/commit/8e9a43d70c90e6a3b110cd0a377296079e4c81f5 | [email protected] | Source CodeVendor |
| https://github.com/element-hq/element-web/security/advisories/GHSA-m6c8-98f4-75rr | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Element Web | All versions |
CPE
Remediation
| |
| Element Desktop | <= 1.11.111 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 16, 2025 | New CVE Received | [email protected] |
Volerion