element-hq Vulnerabilities and Affected Products
Vulnerabilities associated with matrix-authentication-service.
Products
Clear product- synapse11 vulnerabilities
- element-web5 vulnerabilities
- element-android3 vulnerabilities
- element-x-android2 vulnerabilities
- element-call1 vulnerability
- element-desktop1 vulnerability
- element-x-ios1 vulnerability
- ess-helm1 vulnerability
- matrix-authentication-service1 vulnerability
- matrix-tools1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-62425HIGH | Matrix Authentication Service account password can be changed using an authenticated session without supplying the current passwordMAS (Matrix Authentication Service) is a user management and authentication service for Matrix homeservers, written and maintained by Element. A logic flaw in matrix-authentication-service 0.20.0 through 1.4.0 allows an attacker with access to an authenticated MAS session to perform sensitive operations without entering the current password. These include changing the current password, adding or removing an e-mail address and deactivating the account. The vulnerability only affects instances whi… CWE-620Oct 16, 2025 | CVSS8.3v3.1 | EPSS0.422% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |