Mattermost Mobile vulnerabilities

20 known vulnerabilities affecting mattermost/mattermost_mobile.

Total CVEs
20
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH7MEDIUM13

Vulnerabilities

Page 1 of 1
CVE-2025-59480MEDIUMCVSS 6.5fixed in 2.33.02025-11-13
CVE-2025-59480 [MEDIUM] CWE-352 CVE-2025-59480: Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the trusted server, which allows a malicious Mattermost instance or on-path attacker to obtain user session credentials via crafted token-in-URL responses
nvd
CVE-2025-30516HIGHCVSS 7.5fixed in 2.26.02025-04-14
CVE-2025-30516 [LOW] CWE-613 CVE-2025-30516: Mattermost Mobile Apps versions <=2.25.0  fail to terminate sessions during logout under certain con Mattermost Mobile Apps versions <=2.25.0 fail to terminate sessions during logout under certain conditions (e.g. poor connectivity), allowing unauthorized users on shared devices to access sensitive notification content via continued mobile notifications
nvd
CVE-2025-1558MEDIUMCVSS 6.5fixed in 2.25.12025-03-24
CVE-2025-1558 [MEDIUM] CWE-1287 CVE-2025-1558: Mattermost Mobile Apps versions <=2.25.0 fail to properly validate GIF images prior to rendering whi Mattermost Mobile Apps versions <=2.25.0 fail to properly validate GIF images prior to rendering which allows a malicious user to cause the Android application to crash via message containing a maliciously crafted GIF.
nvd
CVE-2025-20630HIGHCVSS 7.5fixed in 2.23.02025-01-16
CVE-2025-20630 [MEDIUM] CWE-1287 CVE-2025-20630: Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields Mattermost Mobile versions <=2.22.0 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the mobile to crash via creating and sending such a post to a channel.
nvd
CVE-2025-20072HIGHCVSS 7.5fixed in 2.23.02025-01-16
CVE-2025-20072 [MEDIUM] CWE-704 CVE-2025-20072: Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an act Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the mobile via crafted malicious input.
nvd
CVE-2025-0476MEDIUMCVSS 4.3fixed in 2.23.02025-01-16
CVE-2025-0476 [MEDIUM] CWE-1287 CVE-2025-0476: Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user who opened a channel containing the specially crafted attachment
nvd
CVE-2025-21083MEDIUMCVSS 6.5fixed in 2.23.02025-01-15
CVE-2025-21083 [MEDIUM] CWE-1287 CVE-2025-21083: Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicio Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
nvd
CVE-2025-20036MEDIUMCVSS 6.5fixed in 2.23.02025-01-15
CVE-2025-20036 [MEDIUM] CWE-1287 CVE-2025-20036: Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicio Mattermost Mobile Apps versions <=2.22.0 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post.
nvd
CVE-2024-11358MEDIUMCVSS 5.5fixed in 2.22.22024-12-16
CVE-2024-11358 [MEDIUM] CWE-284 CVE-2024-11358: Mattermost Android Mobile Apps versions <=2.21.0 fail to properly configure file providers which all Mattermost Android Mobile Apps versions <=2.21.0 fail to properly configure file providers which allows an attacker with local access to access files via file provider.
nvd
CVE-2024-45833MEDIUMCVSS 6.5fixed in 2.19.02024-09-16
CVE-2024-45833 [MEDIUM] CWE-693 CVE-2024-45833: Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the Mattermost Mobile Apps versions <=2.18.0 fail to disable autocomplete during login while typing the password and visible password is selected, which allows the password to get saved in the dictionary when the user has Swiftkey as the default keyboard, the masking is off and the password contains a special character..
nvd
CVE-2024-39767MEDIUMCVSS 6.5fixed in 2.17.02024-07-15
CVE-2024-39767 [MEDIUM] CWE-287 CVE-2024-39767: Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a Mattermost Mobile Apps versions <=2.16.0 fail to validate that the push notifications received for a server actually came from this serve that which allows a malicious server to send push notifications with another server’s diagnostic ID or server URL and have them show up in mobile apps as that server’s push notifications.
nvd
CVE-2024-32945MEDIUMCVSS 5.3fixed in 2.17.02024-07-15
CVE-2024-32945 [LOW] CWE-909 CVE-2024-32945: Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax Mattermost Mobile Apps versions <=2.16.0 fail to protect against abuse of a globally shared MathJax state which allows an attacker to change the contents of a LateX post, by creating another post with specific macro definitions.
nvd
CVE-2024-3872MEDIUMCVSS 6.5≤ 2.13.02024-04-16
CVE-2024-3872 [LOW] CWE-400 CVE-2024-3872: Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexit Mattermost Mobile app versions 2.13.0 and earlier use a regular expression with polynomial complexity to parse certain deeplinks, which allows an unauthenticated remote attacker to freeze or crash the app via a long maliciously crafted link.
nvd
CVE-2024-24975MEDIUMCVSS 6.5fixed in 2.13.0≤ 2.12.02024-03-15
CVE-2024-24975 [LOW] CWE-400 CVE-2024-24975: Uncontrolled Resource Consumption in Mattermost Mobile versions before 2.13.0 fails to limit the siz Uncontrolled Resource Consumption in Mattermost Mobile versions before 2.13.0 fails to limit the size of the code block that will be processed by the syntax highlighter, allowing an attacker to send a very large code block and crash the mobile app.
cvelistv5nvd
CVE-2020-14451HIGHCVSS 7.5fixed in 1.29.02020-06-19
CVE-2020-14451 [HIGH] CWE-459 CVE-2020-14451: An issue was discovered in Mattermost Mobile Apps before 1.29.0. The iOS app allowed Single Sign-On An issue was discovered in Mattermost Mobile Apps before 1.29.0. The iOS app allowed Single Sign-On cookies and Local Storage to remain after a logout, aka MMSA-2020-0013.
nvd
CVE-2020-14449HIGHCVSS 7.5fixed in 1.30.02020-06-19
CVE-2020-14449 [HIGH] CVE-2020-14449: An issue was discovered in Mattermost Mobile Apps before 1.30.0. Authorization tokens can sometimes An issue was discovered in Mattermost Mobile Apps before 1.30.0. Authorization tokens can sometimes be disclosed to third-party servers, aka MMSA-2020-0018.
nvd
CVE-2019-20848HIGHCVSS 7.5fixed in 1.26.02020-06-19
CVE-2019-20848 [HIGH] CWE-20 CVE-2019-20848: An issue was discovered in Mattermost Mobile Apps before 1.26.0. The Quick Reply feature mishandles An issue was discovered in Mattermost Mobile Apps before 1.26.0. The Quick Reply feature mishandles crafted replies.
nvd
CVE-2019-20852HIGHCVSS 7.5fixed in 1.26.02020-06-19
CVE-2019-20852 [HIGH] CWE-532 CVE-2019-20852: An issue was discovered in Mattermost Mobile Apps before 1.26.0. Local logging is not blocked for se An issue was discovered in Mattermost Mobile Apps before 1.26.0. Local logging is not blocked for sensitive information (e.g., server addresses or message content).
nvd
CVE-2019-20850MEDIUMCVSS 5.3fixed in 1.26.02020-06-19
CVE-2019-20850 [MEDIUM] CWE-459 CVE-2019-20850: An issue was discovered in Mattermost Mobile Apps before 1.26.0. A view cache can persist on a devic An issue was discovered in Mattermost Mobile Apps before 1.26.0. A view cache can persist on a device after a logout.
nvd
CVE-2019-20849MEDIUMCVSS 5.3fixed in 1.26.02020-06-19
CVE-2019-20849 [MEDIUM] CWE-459 CVE-2019-20849: An issue was discovered in Mattermost Mobile Apps before 1.26.0. Cookie data can persist on a device An issue was discovered in Mattermost Mobile Apps before 1.26.0. Cookie data can persist on a device after a logout.
nvd