{"id":"CVE-2025-59160","aliases":["GHSA-mp7c-m3rh-r56v"],"url":"https://o3.security/vulnerability/CVE-2025-59160","summary":"matrix-js-sdk has insufficient validation when considering a room to be upgraded by another","details":"Matrix JavaScript SDK is a Matrix Client-Server SDK for JavaScript and TypeScript. matrix-js-sdk before 38.2.0 has insufficient validation of room predecessor links in MatrixClient::getJoinedRooms, allowing a remote attacker to attempt to replace a tombstoned room with an unrelated attacker-supplied room. The issue has been patched and users should upgrade to 38.2.0. A workaround is to avoid using MatrixClient::getJoinedRooms in favor of getRooms() and filtering upgraded rooms separately.","published":"2025-09-16T16:37:54.185Z","modified":"2026-07-15T01:48:58.824133143Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"matrix-js-sdk","fixedVersion":"38.2.0"}],"fix":{"url":"https://github.com/matrix-org/matrix-js-sdk/commit/43c72d5bf5e2d0a26b3b4f71092e7cb39d4137c4","label":"matrix-org/matrix-js-sdk@43c72d5"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/59xxx/CVE-2025-59160.json"},{"type":"ADVISORY","url":"https://github.com/matrix-org/matrix-js-sdk/security/advisories/GHSA-mp7c-m3rh-r56v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59160"},{"type":"FIX","url":"https://github.com/matrix-org/matrix-js-sdk/commit/43c72d5bf5e2d0a26b3b4f71092e7cb39d4137c4"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:48:58.824133143Z"}}