CVE-2024-51750
MEDIUMElement <1.11.85 - Info Disclosure
Title source: llmDescription
Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over federation which can prevent Element Web and Desktop from rendering single messages or the entire room containing them. This was patched in Element Web and Desktop 1.11.85.
Scores
CVSS v3
5.0
EPSS
0.0009
EPSS Percentile
24.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L
Classification
CWE
CWE-248
Status
draft
Timeline
Published
Nov 12, 2024
Tracked Since
Feb 18, 2026