CVE-2024-51750

MEDIUM

Element <1.11.85 - Info Disclosure

Title source: llm
STIX 2.1

Description

Element is a Matrix web client built using the Matrix React SDK. A malicious homeserver can send invalid messages over federation which can prevent Element Web and Desktop from rendering single messages or the entire room containing them. This was patched in Element Web and Desktop 1.11.85.

Scores

CVSS v3 5.0
EPSS 0.0009
EPSS Percentile 24.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-248
Status published
Products (1)
element-hq/element-web < 1.11.85
Published Nov 12, 2024
Tracked Since Feb 18, 2026