CVE-2024-51750 Information
Nov 14, 2024
cve
Description
Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over federation which can prevent Element Web and Desktop from rendering single messages or the entire room containing them. This was patched in Element Web and Desktop 1.11.85.
Reference
https://github.com/element-hq/element-web/security/advisories/GHSA-w36j-v56h-q9pc https://github.com/element-hq/element-web/commit/231073c578d5f92b33cde7aa2b0b9c5836b2dc48
Share on: