{"id":"CVE-2025-48937","aliases":["GHSA-x958-rvg6-956w","RUSTSEC-2025-0041"],"url":"https://o3.security/vulnerability/CVE-2025-48937","summary":"matrix-sdk-crypto vulnerable to sender of encrypted events being spoofed by homeserver administrator","details":"### Summary\n\nmatrix-sdk-crypto since version 0.8.0 up to 0.11.0 does not correctly validate the sender of an encrypted event. Accordingly, a malicious homeserver operator can modify events served to clients, making those events appear to the recipient as if they were sent by another user.\n\nAlthough the CVSS score is 4.9 (AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N), we consider this a High Severity security issue.\n\n### Details\n\nThe Matrix specification [requires](https://spec.matrix.org/v1.14/client-server-api/#mmegolmv1aes-sha2) that clients ensure that \"the event’s `sender`, `room_id`, and the recorded `session_id` match a trusted session\". The vulnerable matrix-sdk-crypto versions check that the `room_id` matches that of the session denoted by `session_id`, but do not check the `sender`.\n\n### Patches\n\nThe issue is resolved by [13c1d20](https://github.com/matrix-org/matrix-rust-sdk/commit/13c1d2048286bbabf5e7bc6b015aafee98f04d55), included in versions 0.11.1 and 0.12.0 of matrix-sdk-crypto.\n\n### Workarounds\n\nSince a successful attack requires administrator access to the homeserver, users who trust the administrators of their local homeserver are not affected.\n\n### References\n\n * https://spec.matrix.org/v1.14/client-server-api/#mmegolmv1aes-sha2","published":"2025-06-10T15:32:00.822Z","modified":"2026-08-12T03:51:49.498115153Z","cvss":{"score":4.9,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N"},"epss":{"score":0.00323,"percentile":0.24599,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"matrix-sdk-crypto","fixedVersion":"0.11.1"}],"fix":{"url":"https://github.com/matrix-org/matrix-rust-sdk/commit/13c1d2048286bbabf5e7bc6b015aafee98f04d55","label":"matrix-org/matrix-rust-sdk@13c1d20"},"references":[{"type":"WEB","url":"https://spec.matrix.org/v1.14/client-server-api/#mmegolmv1aes-sha2"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/48xxx/CVE-2025-48937.json"},{"type":"ADVISORY","url":"https://github.com/matrix-org/matrix-rust-sdk/security/advisories/GHSA-x958-rvg6-956w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-48937"},{"type":"FIX","url":"https://github.com/matrix-org/matrix-rust-sdk/commit/13c1d2048286bbabf5e7bc6b015aafee98f04d55"},{"type":"FIX","url":"https://github.com/matrix-org/matrix-rust-sdk/commit/56980745b4f27f7dc72ac296e6aa003e5d92a75b"},{"type":"PACKAGE","url":"https://github.com/matrix-org/matrix-rust-sdk"},{"type":"WEB","url":"https://rustsec.org/advisories/RUSTSEC-2025-0041.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:49.498115153Z"}}