CVE-2026-55850EPSS p43.9%
CVE-2026-55850CVE-2026-55850
Description
Element Web is a Matrix web client built using the Matrix React SDK. Prior to 1.12.22, EmbeddedPage in apps/web/src/components/structures/EmbeddedPage.tsx renders homeserver-supplied homepage content through dangerouslySetInnerHTML without passing it through sanitizedHtmlNode. A malicious homeserver can provide crafted HTML that Element Web renders on the homepage; the content security policy prevents JavaScript but not phishing HTML. This issue is fixed in version 1.12.22.
Scoring
| EPSS | 0.55% probability of exploitation · percentile 43.9% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-30 |