GHSA-h97m-27fx-42rx
matrix-sdk-ui: Incomplete edit validation
Details
### Impact The message edit validation logic in the `matrix-sdk-ui` crate before 0.16.1 is missing a check: when replacing an encrypted event, the replacement event itself is not required to be encrypted. This enables a malicious homeserver administrator (or an actor with equivalent power) to impersonate or spoof messages as if they were sent by a victim user.
### Patches `matrix-sdk-ui` 0.16.1 fixes the message edit validation logic to align with the algorithm for replacement events[^1] described in the Matrix specification.
### Workarounds N/A
### References * Pull request: https://github.com/matrix-org/matrix-rust-sdk/pull/6454
### For more information If you have any questions or comments about this advisory, please email us at [security at matrix.org](mailto:security@matrix.org).
[^1]: https://spec.matrix.org/unstable/client-server-api/#validity-of-replacement-events
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.16.1Upgrade matrix-sdk-ui to 0.16.1 or newer (ecosystem crates.io).
References
- https://github.com/matrix-org/matrix-rust-sdk/security/advisories/GHSA-h97m-27fx-42rx[WEB]
- https://github.com/matrix-org/matrix-rust-sdk/pull/6454[WEB]
- https://github.com/matrix-org/matrix-rust-sdk[PACKAGE]
- https://github.com/matrix-org/matrix-rust-sdk/releases/tag/matrix-sdk-0.16.1[WEB]
- https://rustsec.org/advisories/RUSTSEC-2026-0158.html[WEB]