matrix-js-sdk can be tricked into disclosing E2EE room keys to a participating homeserver
Modified: 11/8/2023
package
pkg:npm/matrix-js-sdk
matrix-js-sdk can be tricked into disclosing E2EE room keys to a participating homeserver
Modified: 11/8/2023
Matrix JavaScript SDK's key history sharing could share keys to malicious devices
Modified: 10/15/2024
matrix-js-sdk subject to user impersonation due to key/device identifier confusion in SAS verification
Modified: 11/8/2023
matrix-js-sdk subject to impersonated messages due to permissive key forwarding
Modified: 11/8/2023
matrix-js-sdk vulnerable to invisible eavesdropping in group calls
Modified: 9/10/2026
Improper beacon events in matrix-js-sdk can result in availability issues
Modified: 11/8/2023
matrix-js-sdk has insufficient validation when considering a room to be upgraded by another
Modified: 9/22/2025
Prototype pollution in matrix-js-sdk (part 2)
Modified: 9/10/2026
matrix-js-sdk subject to user spoofing via Olm/Megolm protocol confusion
Modified: 11/8/2023
matrix-js-sdk Prototype Pollution vulnerability
Modified: 11/8/2023
matrix-js-sdk will freeze when a user sets a room with itself as a its predecessor
Modified: 8/20/2024
matrix-js-sdk has insufficient MXC URI validation which allows client-side path traversal
Modified: 11/4/2025