CVE-2022-39251
Matrix Javascript SDK is the Matrix Client-Server SDK for JavaScript. Prior to version 19.7.0, an attacker cooperating with a malicious homeserver can construct messages that legitimately appear to have come from another person, without any indication such as a grey shield. Additionally, a sophisticated attacker cooperating with a malicious homeserver could employ this vulnerability to perform a targeted attack in order to send fake to-device messages appearing to originate from another user. This can allow, for example, to inject the key backup secret during a self-verification, to make a targeted device start using a malicious key backup spoofed by the homeserver. These attacks are possible due to a protocol confusion vulnerability that accepts to-device messages encrypted with Megolm instead of Olm. Starting with version 19.7.0, matrix-js-sdk has been modified to only accept Olm-encrypted to-device messages. Out of caution, several other checks have been audited or added. This attack requires coordination between a malicious home server and an attacker, so those who trust their home servers do not need a workaround.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.6
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
- EPSS probability
- 0.36%
- CWE
- CWE-322, CWE-287
- Published
- 2022-09-28
- Last modified
- 2026-03-13
Affected products
- matrix-org matrix-js-sdk
Weakness type
Related vulnerabilities
- CVE-2025-20163 — Cisco Nexus Dashboard Fabric Controller SSH Host Key Vulnerability
- CVE-2022-39255 — Matrix iOS SDK vulnerable ton Olm/Megolm protocol confusion
- CVE-2022-39254 — When matrix-nio receives forwarded room keys, the receiver doesn't check if it requested the key from the forwarder
- CVE-2022-39252 — When matrix-rust-sdk recieves forwarded room keys, the reciever doesn't check if it requested the key from the forwarder
- CVE-2022-39250 — Matrix JavaScript SDK vulnerable to key/device identifier confusion in SAS verification
- CVE-2022-39248 — matrix-android-sdk2 vulnerable to Olm/Megolm protocol confusion
- CVE-2024-47519 — Backup uploads to ETM subject to man-in-the-middle interception
- CVE-2026-1709 — Keylime: keylime: authentication bypass allows unauthorized administrative operations due to missing client-side tls authentication