—
RUSTSEC-2025-0043
matrix-sdk-sqlite: SQL injection vulnerability in `SqliteEventCacheStore::find_event_with_relations`
Details
The `SqliteEventCacheStore::find_event_with_relations` function constructs SQL queries using `format!()` with unescaped input, allowing an attacker to inject arbitrary SQL. This results in a SQL injection vulnerability.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/matrix-sdk-sqlite
Introduced in:
0.11.0Fixed in: 0.13.0Upgrade matrix-sdk-sqlite to 0.13.0 or newer (ecosystem crates.io).