Impact
Versions of Element Web and Desktop earlier than 1.11.85 do not check if thumbnails for attachments, stickers and images are coherent. It is possible to add thumbnails to events trigger a file download once clicked.
Patches
Fixed in element-web 1.11.85.
Workarounds
Inspect the type of downloaded files before opening them.
References
N/A
Impact
Versions of Element Web and Desktop earlier than 1.11.85 do not check if thumbnails for attachments, stickers and images are coherent. It is possible to add thumbnails to events trigger a file download once clicked.
Patches
Fixed in element-web 1.11.85.
Workarounds
Inspect the type of downloaded files before opening them.
References
N/A