{"id":"CVE-2026-55850","title":"Element Web is a Matrix web client built using the Matrix React SDK","summary":"Element Web is a Matrix web client built using the Matrix React SDK. Prior to 1.12.22, EmbeddedPage in apps/web/src/components/structures/EmbeddedPage.tsx renders homeserver-supplied homepage content through dangerouslySetInnerHTML witho…","severity":"none","cwe":["CWE-79"],"published":"2026-08-21","updated":"2026-09-30","sourceUpdated":"2026-09-30T19:57:08.043","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-55850","references":[{"url":"https://github.com/element-hq/element-web/commit/7949980a7e3c7e397d7afe899ef1b0563c417b0e","label":"security-advisories@github.com"},{"url":"https://github.com/element-hq/element-web/releases/tag/v1.12.22","label":"security-advisories@github.com"},{"url":"https://github.com/element-hq/element-web/security/advisories/GHSA-wrcp-5v3v-3j6v","label":"security-advisories@github.com"},{"url":"https://www.machinespirits.com/advisory/563a17","label":"security-advisories@github.com"}],"tags":["nvd"],"epss":0.00547,"epssPercentile":0.43733,"ingestedAt":"2026-09-30T20:23:19.467Z","slug":"CVE-2026-55850","body":"## Overview\n\nElement Web is a Matrix web client built using the Matrix React SDK. Prior to 1.12.22, EmbeddedPage in apps/web/src/components/structures/EmbeddedPage.tsx renders homeserver-supplied homepage content through dangerouslySetInnerHTML without passing it through sanitizedHtmlNode. A malicious homeserver can provide crafted HTML that Element Web renders on the homepage; the content security policy prevents JavaScript but not phishing HTML. This issue is fixed in version 1.12.22.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}