MEDIUM
GHSA-mp7c-m3rh-r56v
matrix-js-sdk has insufficient validation when considering a room to be upgraded by another
Quick fix
GHSA-mp7c-m3rh-r56v — matrix-js-sdk: upgrade to the fixed version with the command below.
npm install matrix-js-sdk@38.2.0Details
### Impact matrix-js-sdk before 38.2.0 has insufficient validation of room predecessor links in `MatrixClient::getJoinedRooms`, allowing a remote attacker to attempt to replace a tombstoned room with an unrelated attacker-supplied room.
### Patches The issue has been patched and users should upgrade to 38.2.0.
### Workarounds Avoid using `MatrixClient::getJoinedRooms` in favour of `getRooms()` and filtering upgraded rooms separately.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/matrix-org/matrix-js-sdk/security/advisories/GHSA-mp7c-m3rh-r56v[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2025-59160[ADVISORY]
- https://github.com/matrix-org/matrix-js-sdk/commit/43c72d5bf5e2d0a26b3b4f71092e7cb39d4137c4[WEB]
- https://github.com/matrix-org/matrix-js-sdk[PACKAGE]
- https://github.com/matrix-org/matrix-js-sdk/releases/tag/v38.2.0[WEB]
- https://www.npmjs.com/package/matrix-js-sdk/v/38.2.0[WEB]