cbcvebase.
CVE-2025-9072
published 2025-09-15

CVE-2025-9072: Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, allowing an attacker to craft a…

PriorityP428medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.16%
5.7th percentile
Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, allowing an attacker to craft a malicious link that, once a user authenticates with their SAML provider, could post the user’s cookies to an attacker-controlled URL.

Affected

16 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server>= 10.10.0 < 10.10.210.10.2
github.commattermost_mattermost-server>= 10.10.0+incompatible < 10.10.2+incompatible10.10.2+incompatible
github.commattermost_mattermost-server>= 10.5.0 < 10.5.1010.5.10
github.commattermost_mattermost-server>= 10.5.0+incompatible < 10.5.10+incompatible10.5.10+incompatible
github.commattermost_mattermost-server>= 10.9.0 < 10.9.510.9.5
github.commattermost_mattermost-server>= 10.9.0+incompatible < 10.9.5+incompatible10.9.5+incompatible
github.commattermost_mattermost_server_v8>= 0 < 8.0.0-20250731063404-9eebaadf8f728.0.0-20250731063404-9eebaadf8f72
mattermostmattermost10.10.0 – 10.10.1
mattermostmattermost10.5.0 – 10.5.9
mattermostmattermost10.9.0 – 10.9.4
mattermostmattermost_server>= 10.10.0 < 10.10.210.10.2
mattermostmattermost_server>= 10.5.0 < 10.5.1010.5.10
mattermostmattermost_server>= 10.9.0 < 10.9.510.9.5
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_binutils_2.32-4_on_cbl_mariner_1.0

CVSS provenance

nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
vendor_msrc5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.