{"id":"CVE-2026-55850","summary":"Element Web: A malicious homeserver can inject HTML in Element Web using its homepage","details":"Element Web is a Matrix web client built using the Matrix React SDK. Prior to 1.12.22, EmbeddedPage in apps/web/src/components/structures/EmbeddedPage.tsx renders homeserver-supplied homepage content through dangerouslySetInnerHTML without passing it through sanitizedHtmlNode. A malicious homeserver can provide crafted HTML that Element Web renders on the homepage; the content security policy prevents JavaScript but not phishing HTML. This issue is fixed in version 1.12.22.","aliases":["GHSA-wrcp-5v3v-3j6v"],"modified":"2026-08-23T03:49:32.596126226Z","published":"2026-08-21T18:30:12.251Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-79"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55850.json"},"references":[{"type":"WEB","url":"https://github.com/element-hq/element-web/releases/tag/v1.12.22"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/55xxx/CVE-2026-55850.json"},{"type":"ADVISORY","url":"https://github.com/element-hq/element-web/security/advisories/GHSA-wrcp-5v3v-3j6v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-55850"},{"type":"ADVISORY","url":"https://www.machinespirits.com/advisory/563a17"},{"type":"FIX","url":"https://github.com/element-hq/element-web/commit/7949980a7e3c7e397d7afe899ef1b0563c417b0e"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/element-hq/element-web","events":[{"introduced":"0"},{"fixed":"7949980a7e3c7e397d7afe899ef1b0563c417b0e"},{"fixed":"94636e8d4d9e7fe96d2d598456551f4847f3bbba"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"1.12.22"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v1.12.22-rc.0","v1.11.68","v1.11.68-rc.0","v1.11.35-no-media-devices-hotfix","no-media-devices-release","v1.9.5","v1.9.5-rc.1","v1.7.30","v1.7.30-rc.1","v1.7.23","v1.7.23-rc.1","v1.7.16","v1.7.16-rc.1","v1.7.14","v1.7.14-rc.1","v1.7.13","v1.7.13-rc.1","v1.7.11","v1.7.11-rc.1","v1.7.9","v1.7.9-rc.1","v1.7.2","v1.7.1","v1.7.0","v1.5.10","v1.5.3","v1.4.2","v1.4.2-rc.1","v1.4.1","v1.4.0","v1.4.0-rc.2","v1.4.0-rc.1","v0.17.8","v0.17.8-rc.1","v0.16.3","v0.16.3-rc.2","v0.16.3-rc.1","v0.16.0","v0.16.0-rc.2","v0.16.0-rc.1","v0.15.5","v0.15.5-rc.1","v0.15.4","v0.15.4-rc.1","v0.15.1","v0.15.0","v0.15.0-rc.6","v0.15.0-rc.5","v0.15.0-rc.4","v0.15.0-rc.3","v0.15.0-rc.2","v0.15.0-rc.1","v0.14.3-rc.1","v0.12.2","v0.12.1","v0.12.1-rc.1","v0.12.0-rc.1","v0.10.0","v0.10.0-rc.2","v0.9.3","v0.9.2","v0.8.3","v0.8.2","v0.8.1","v0.8.0","v0.7.5-r1","v0.7.5","v0.7.4-r1","v0.7.4","v0.7.3","v0.7.2","v0.7.1","v0.7.0","v0.6.1","v0.6.0","v0.5.0","v0.4.1","v0.4.0","v0.3.0","v0.1.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-55850.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}