(Incidentally, this is also the incantation that will cause its primary maintainer to show up in the comment thread and tell me that I’m not using their seemingly annual complete new client rewrite that fixes all of the problems and makes it perfect now.)
Soatok covered it very well here: https://soatok.blog/2024/08/14/security-issues-in-matrixs-ol...
I'm quite sure most of these issues were fixed by now, but the fundamental issues remain, at least in this federation.