cbcvebase.
CVE-2025-9072
published 2025-09-15

CVE-2025-9072: Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, allowing an attacker to craft a…

medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, allowing an attacker to craft a malicious link that, once a user authenticates with their SAML provider, could post the user’s cookies to an attacker-controlled URL.

Affected

16 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-server>= 10.10.0 < 10.10.210.10.2
github.commattermost_mattermost-server>= 10.10.0+incompatible < 10.10.2+incompatible10.10.2+incompatible
github.commattermost_mattermost-server>= 10.5.0 < 10.5.1010.5.10
github.commattermost_mattermost-server>= 10.5.0+incompatible < 10.5.10+incompatible10.5.10+incompatible
github.commattermost_mattermost-server>= 10.9.0 < 10.9.510.9.5
github.commattermost_mattermost-server>= 10.9.0+incompatible < 10.9.5+incompatible10.9.5+incompatible
github.commattermost_mattermost_server_v8>= 0 < 8.0.0-20250731063404-9eebaadf8f728.0.0-20250731063404-9eebaadf8f72
mattermostmattermost10.10.0 – 10.10.1
mattermostmattermost10.5.0 – 10.5.9
mattermostmattermost10.9.0 – 10.9.4
mattermostmattermost_server>= 10.10.0 < 10.10.210.10.2
mattermostmattermost_server>= 10.5.0 < 10.5.1010.5.10
mattermostmattermost_server>= 10.9.0 < 10.9.510.9.5
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_binutils_2.32-4_on_cbl_mariner_1.0