CVE-2025-21088

Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the frontend via crafted malicious input.
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:10.2.0:-:*:*:*:*:*:*

History

30 Sep 2025, 15:52

Type Values Removed Values Added
References () https://mattermost.com/security-updates - () https://mattermost.com/security-updates - Vendor Advisory
CPE cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
cpe:2.3:a:mattermost:mattermost_server:10.2.0:-:*:*:*:*:*:*
Summary
  • (es) Las versiones de Mattermost 10.2.x &lt;= 10.2.0, 9.11.x &lt;= 9.11.5, 10.0.x &lt;= 10.0.3, 10.1.x &lt;= 10.1.3 no logran validar correctamente el estilo del proto suministrado al estilo de una acción en post.props.attachments, lo que permite que un atacante bloquee el frontend a través de una entrada maliciosa manipulada.
First Time Mattermost
Mattermost mattermost Server

15 Jan 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-15 16:15

Updated : 2025-09-30 15:52


NVD link : CVE-2025-21088

Mitre link : CVE-2025-21088

CVE.ORG link : CVE-2025-21088


JSON object : View

Products Affected

mattermost

  • mattermost_server
CWE
CWE-704

Incorrect Type Conversion or Cast