CVE-2025-48937
matrix-sdk-crypto vulnerable to encrypted event sender spoofing by homeserver administrator
4.9
MEDIUM
CVSS 3.1
EPSS 0.31%
Description
matrix-sdk-crypto versions 0.8.0 up to and including 0.11.0 does not correctly validate the sender of an encrypted event. Accordingly, a malicious homeserver operator can modify events served to clients, making those events appear to the recipient as if they were sent by another user. Although the CVSS score is 4.9 (AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N), we consider this a High severity security issue.
How to fix CVE-2025-48937
To remediate CVE-2025-48937, upgrade the affected package to a fixed version below.
- —upgrade to 0.11.1 or later
- —upgrade to 0.11.1 or later
Is CVE-2025-48937 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- >= 0.8.0, < 0.11.1
- >= 0.8.0, < 0.11.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM4.9 | CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N |