CVE-2025-21088
published 2025-01-15CVE-2025-21088: Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's…
PriorityP335medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.55%
42.7th percentile
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the frontend via crafted malicious input.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 10.0.0+incompatible < 10.0.4+incompatible | 10.0.4+incompatible |
| github.com | mattermost_mattermost-server | >= 10.1.0+incompatible < 10.1.4+incompatible | 10.1.4+incompatible |
| github.com | mattermost_mattermost-server | >= 10.2.0+incompatible < 10.2.1+incompatible | 10.2.1+incompatible |
| github.com | mattermost_mattermost-server | >= 9.11.0+incompatible < 9.11.6+incompatible | 9.11.6+incompatible |
| github.com | mattermost_mattermost_server_v8 | >= 0 < 8.0.0-20241127161322-25ff7a3779a5 | 8.0.0-20241127161322-25ff7a3779a5 |
| github.com | mattermost_mattermost_server_v8 | >= 10.0.0 < 10.0.4 | 10.0.4 |
| github.com | mattermost_mattermost_server_v8 | >= 10.1.0 < 10.1.4 | 10.1.4 |
| github.com | mattermost_mattermost_server_v8 | >= 10.2.0 < 10.2.1 | 10.2.1 |
| github.com | mattermost_mattermost_server_v8 | >= 9.11.0 < 9.11.6 | 9.11.6 |
| mattermost | mattermost | — | — |
| mattermost | mattermost | 10.0.0 – 10.0.3 | — |
| mattermost | mattermost | 10.1.0 – 10.1.3 | — |
| mattermost | mattermost | 9.11.0 – 9.11.5 | — |
| mattermost | mattermost_server | — | — |
| mattermost | mattermost_server | >= 10.0.0 < 10.0.4 | 10.0.4 |
| mattermost | mattermost_server | >= 10.1.0 < 10.1.4 | 10.1.4 |
| mattermost | mattermost_server | >= 9.11.0 < 9.11.6 | 9.11.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost Incorrect Type Conversion or Cast in github.com/mattermost/mattermost-server
osv·2025-01-16
CVE-2025-21088 Mattermost Incorrect Type Conversion or Cast in github.com/mattermost/mattermost-server
Mattermost Incorrect Type Conversion or Cast in github.com/mattermost/mattermost-server
Mattermost Incorrect Type Conversion or Cast in github.com/mattermost/mattermost-server
OSV
Mattermost Incorrect Type Conversion or Cast
osv·2025-01-15
CVE-2025-21088 [MEDIUM] Mattermost Incorrect Type Conversion or Cast
Mattermost Incorrect Type Conversion or Cast
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the frontend via crafted malicious input.
GHSA
Mattermost Incorrect Type Conversion or Cast
ghsa·2025-01-15
CVE-2025-21088 [MEDIUM] CWE-704 Mattermost Incorrect Type Conversion or Cast
Mattermost Incorrect Type Conversion or Cast
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the frontend via crafted malicious input.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-15
Published