{"id":"GHSA-mp7c-m3rh-r56v","summary":"matrix-js-sdk has insufficient validation when considering a room to be upgraded by another","details":"### Impact\nmatrix-js-sdk before 38.2.0 has insufficient validation of room predecessor links in `MatrixClient::getJoinedRooms`, allowing a remote attacker to attempt to replace a tombstoned room with an unrelated attacker-supplied room.\n\n### Patches\nThe issue has been patched and users should upgrade to 38.2.0.\n\n### Workarounds\nAvoid using `MatrixClient::getJoinedRooms` in favour of `getRooms()` and filtering upgraded rooms separately.","aliases":["CVE-2025-59160"],"modified":"2025-09-22T22:59:23Z","published":"2025-09-16T20:18:57Z","database_specific":{"cwe_ids":["CWE-20","CWE-345","CWE-862"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-09-16T20:18:57Z","nvd_published_at":"2025-09-16T17:15:41Z"},"references":[{"type":"WEB","url":"https://github.com/matrix-org/matrix-js-sdk/security/advisories/GHSA-mp7c-m3rh-r56v"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-59160"},{"type":"WEB","url":"https://github.com/matrix-org/matrix-js-sdk/commit/43c72d5bf5e2d0a26b3b4f71092e7cb39d4137c4"},{"type":"PACKAGE","url":"https://github.com/matrix-org/matrix-js-sdk"},{"type":"WEB","url":"https://github.com/matrix-org/matrix-js-sdk/releases/tag/v38.2.0"},{"type":"WEB","url":"https://www.npmjs.com/package/matrix-js-sdk/v/38.2.0"}],"affected":[{"package":{"name":"matrix-js-sdk","ecosystem":"npm","purl":"pkg:npm/matrix-js-sdk"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"38.2.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-mp7c-m3rh-r56v/GHSA-mp7c-m3rh-r56v.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}