cbcvebase.
CVE-2025-21088
published 2025-01-15

CVE-2025-21088: Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's…

PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.55%
42.7th percentile
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the frontend via crafted malicious input.

Affected

17 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server>= 10.0.0+incompatible < 10.0.4+incompatible10.0.4+incompatible
github.commattermost_mattermost-server>= 10.1.0+incompatible < 10.1.4+incompatible10.1.4+incompatible
github.commattermost_mattermost-server>= 10.2.0+incompatible < 10.2.1+incompatible10.2.1+incompatible
github.commattermost_mattermost-server>= 9.11.0+incompatible < 9.11.6+incompatible9.11.6+incompatible
github.commattermost_mattermost_server_v8>= 0 < 8.0.0-20241127161322-25ff7a3779a58.0.0-20241127161322-25ff7a3779a5
github.commattermost_mattermost_server_v8>= 10.0.0 < 10.0.410.0.4
github.commattermost_mattermost_server_v8>= 10.1.0 < 10.1.410.1.4
github.commattermost_mattermost_server_v8>= 10.2.0 < 10.2.110.2.1
github.commattermost_mattermost_server_v8>= 9.11.0 < 9.11.69.11.6
mattermostmattermost
mattermostmattermost10.0.0 – 10.0.3
mattermostmattermost10.1.0 – 10.1.3
mattermostmattermost9.11.0 – 9.11.5
mattermostmattermost_server
mattermostmattermost_server>= 10.0.0 < 10.0.410.0.4
mattermostmattermost_server>= 10.1.0 < 10.1.410.1.4
mattermostmattermost_server>= 9.11.0 < 9.11.69.11.6
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.