PT-2026-79429 · Element · Element Web
CVE-2026-55850
·
Published
2026-08-21
·
Updated
2026-08-21
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Element Web versions prior to 1.12.22
Description
The
EmbeddedPage component in apps/web/src/components/structures/EmbeddedPage.tsx renders homepage content supplied by the homeserver using dangerouslySetInnerHTML without utilizing sanitizedHtmlNode. This allows a malicious homeserver to provide crafted HTML that is rendered on the homepage. While the content security policy blocks JavaScript execution, it does not prevent the rendering of phishing HTML.Recommendations
Update to version 1.12.22.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Element Web