CVE-2025-59160: Matrix-Org Matrix-Js-SDK

Low severity, CVSS 2.7. EPSS: 0.2% chance of exploitation in the next 30 days.

Matrix JavaScript SDK is a Matrix Client-Server SDK for JavaScript and TypeScript. matrix-js-sdk before 38.2.0 has insufficient validation of room predecessor links in MatrixClient::getJoinedRooms, allowing a remote attacker to attempt to replace a tombstoned room with an unrelated attacker-supplied room. The issue has been patched and users should upgrade to 38.2.0. A workaround is to avoid using MatrixClient::getJoinedRooms in favor of getRooms() and filtering upgraded rooms separately.

Affected products

  • Matrix-Org Matrix-Js-SDK: before 38.2.0 (fixed in 38.2.0)

Published 2025-09-16. Last modified 2026-06-17.