Loading HuntDB...

GHSA-qcvh-p9jq-wp8v

GitHub Security Advisory

Malicious homeservers can steal message keys when the matrix-react-sdk user invites another user to a room

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

### Impact

matrix-react-sdk before 3.102.0 allows a malicious homeserver to potentially steal message keys for a room when a user invites another user to that room, via injection of a malicious device controlled by the homeserver. This is possible because matrix-react-sdk before 3.102.0 shared historical message keys on invite.

### Patches

matrix-react-sdk 3.102.0 [disables sharing message keys on invite](https://github.com/matrix-org/matrix-react-sdk/pull/12618) by removing calls to the vulnerable functionality.

### Workarounds

None.

### References

The vulnerability in matrix-react-sdk is caused by calling `MatrixClient.sendSharedHistoryKeys` in matrix-js-sdk, which is inherently vulnerable to this sort of attack. This matrix-js-sdk vulnerability is tracked as CVE-2024-47080 / [GHSA-4jf8-g8wp-cx7c](https://github.com/matrix-org/matrix-js-sdk/security/advisories/GHSA-4jf8-g8wp-cx7c). Given that this functionality is not specific to sharing message keys on *invite*, is optional, has to be explicitly called by the caller and has been independently patched in matrix-react-sdk by removing the offending calls, we believe it is proper to treat the matrix-react-sdk vulnerability as a separate one, with its own advisory and CVE.

The matrix-org/matrix-react-sdk repository has recently been archived and the project was moved to [element-hq/matrix-react-sdk](https://github.com/element-hq/matrix-react-sdk). Given that this happened *after* the first patched release, no releases of the project on [element-hq/matrix-react-sdk](https://github.com/element-hq/matrix-react-sdk) were ever vulnerable to this vulnerability.

Patching pull request: https://github.com/matrix-org/matrix-react-sdk/pull/12618.

### For more information

If you have any questions or comments about this advisory, please email us at security at [security at matrix.org](mailto:[email protected]).

Affected Packages

npm matrix-react-sdk
Affected versions: 3.18.0 (fixed in 3.102.0)

Related CVEs

Key Information

GHSA ID
GHSA-qcvh-p9jq-wp8v
Published
October 15, 2024 6:11 PM
Last Modified
October 15, 2024 7:56 PM
CVSS Score
7.5 /10
Primary Ecosystem
npm
Primary Package
matrix-react-sdk
GitHub Reviewed
✓ Yes

Dataset

Last updated: September 12, 2025 6:34 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.