VDB
Sign up
—

RUSTSEC-2025-0043

matrix-sdk-sqlite: SQL injection vulnerability in `SqliteEventCacheStore::find_event_with_relations`

Details

The `SqliteEventCacheStore::find_event_with_relations` function constructs SQL queries using `format!()` with unescaped input, allowing an attacker to inject arbitrary SQL. This results in a SQL injection vulnerability.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/matrix-sdk-sqlite
Introduced in: 0.11.0Fixed in: 0.13.0

Upgrade matrix-sdk-sqlite to 0.13.0 or newer (ecosystem crates.io).

References