Intel

AIKIDO-2025-10688

matrix-synapse is vulnerable to Open Redirect

Open Redirect Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Oct 9, 2025

51

Medium Risk

This Affects:

PYTHONmatrix-synapse
1.120.0 - 1.138.3
Fixed in 1.139.0
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to open redirect attacks due to insufficient validation of the idp parameter in the legacy SSO flow. The vulnerability is mitigated by restricting the idp parameter to known values defined in the configuration file and by URL-encoding it to prevent malicious redirection.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

matrix-synapse is vulnerable to Open Redirect in versions 1.120.0 - 1.138.3.

How to fix this

Upgrade the matrix-synapse library to the patch version.