CVE-2025-54525
published 2025-08-11CVE-2025-54525: Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to create…
PriorityP338high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.34%
25.5th percentile
Mattermost Confluence Plugin version <1.5.0 fails to handle unexpected request body which allows attackers to crash the plugin via constant hit to create channel subscription endpoint with an invalid request body.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-plugin-confluence | >= 0 < 1.5.0 | 1.5.0 |
| mattermost | confluence | < 1.5.0 | 1.5.0 |
| mattermost | mattermost_confluence_plugin | < 1.5.0 | 1.5.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost Confluence Plugin has Improper Validation of Specified Type of Input in github.com/mattermost/mattermost-plugin-confluence
osv·2025-08-18
CVE-2025-54525 Mattermost Confluence Plugin has Improper Validation of Specified Type of Input in github.com/mattermost/mattermost-plugin-confluence
Mattermost Confluence Plugin has Improper Validation of Specified Type of Input in github.com/mattermost/mattermost-plugin-confluence
Mattermost Confluence Plugin has Improper Validation of Specified Type of Input in github.com/mattermost/mattermost-plugin-confluence
GHSA
Mattermost Confluence Plugin has Improper Validation of Specified Type of Input
ghsa·2025-08-11
CVE-2025-54525 [HIGH] CWE-1287 Mattermost Confluence Plugin has Improper Validation of Specified Type of Input
Mattermost Confluence Plugin has Improper Validation of Specified Type of Input
Mattermost Confluence Plugin versions < 1.5.0 fail to handle unexpected request bodies, allowing attackers to crash the plugin via constant hits to the create channel subscription endpoint with an invalid request body.
OSV
Mattermost Confluence Plugin has Improper Validation of Specified Type of Input
osv·2025-08-11
CVE-2025-54525 [HIGH] Mattermost Confluence Plugin has Improper Validation of Specified Type of Input
Mattermost Confluence Plugin has Improper Validation of Specified Type of Input
Mattermost Confluence Plugin versions < 1.5.0 fail to handle unexpected request bodies, allowing attackers to crash the plugin via constant hits to the create channel subscription endpoint with an invalid request body.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-11
Published