PT-2026-79429 · Element · Element Web

CVE-2026-55850

·

Published

2026-08-21

·

Updated

2026-08-21

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Element Web versions prior to 1.12.22
Description The EmbeddedPage component in apps/web/src/components/structures/EmbeddedPage.tsx renders homepage content supplied by the homeserver using dangerouslySetInnerHTML without utilizing sanitizedHtmlNode. This allows a malicious homeserver to provide crafted HTML that is rendered on the homepage. While the content security policy blocks JavaScript execution, it does not prevent the rendering of phishing HTML.
Recommendations Update to version 1.12.22.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55850
GHSA-WRCP-5V3V-3J6V

Affected Products

Element Web