Element allows a malicious homeserver can modify events leading to unrenderable events or rooms
Vulnerability Description
Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over federation which can prevent Element Web and Desktop from rendering single messages or the entire room containing them. This was patched in Element Web and Desktop 1.11.85.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-51750
Credits & Attribution
No credits recorded in the NVD database.
References
More from element-hq
View All →Affected Vendor
element-hq
View all reports →