CVE-2025-59161 - CVE House
Back to Database
Status published Low CVE-2025-59161

In Element Web and Element Desktop, a malicious room can hide an unrelated room and cause it to be left when the malicious room is left

Vulnerability Description

Element Web is a Matrix web client built using the Matrix React SDK. Element Web and Element Desktop before version 1.11.112 have insufficient validation of room predecessor links, allowing a remote attacker to attempt to impermanently replace a room's entry in the room list with an unrelated attacker-supplied room. While the effect of this is temporary, it may still confuse users into acting on incorrect assumptions. The issue has been patched and users should upgrade to 1.11.112. A reload/refresh will fix the incorrect room list state, removing the attacker's room and restoring the original room.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-59161

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

element-web
Vulnerable Versions:
< 1.11.112

Timeline

Official Publish: September 16th, 2025
Last Modified: September 16th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)