Intel

AIKIDO-2025-10552

matrix-synapse is vulnerable to Improper Handling of Insufficient Permissions or Privileges

Improper Handling of Insufficient Permissions or PrivilegesCVE-2025-49090 Published Aug 13, 2025

85

High Risk

This Affects:

PYTHONmatrix-synapse
0.0.1 - 1.135.0
Fixed in 1.135.2
Are you affected? Scan for Free

TL;DR

Two high-severity protocol vulnerabilities in state resolution will be fixed via an off-cycle Matrix spec update that introduces room v12, with coordinated server releases scheduled for Aug 11, 2025 and embargo lift on Aug 14, 2025 — operators of publicly federated homeservers should prepare to upgrade promptly.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

matrix-synapse is vulnerable to Improper Handling of Insufficient Permissions or Privileges in versions 0.0.1 - 1.135.0.

How to fix this

Upgrade the matrix-synapse library to the patch version.