CVE-2025-21088
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-21088 is a vulnerability affecting Mattermost versions 10.2.x up to 10.2.0, 9.11.x up to 9.11.5, 10.0.x up to 10.0.3, and 10.1.x up to 10.1.3. This issue arises from the software's failure to adequately validate the style of proto supplied to an action's style in post.props.attachments. An attacker can exploit this vulnerability by providing maliciously crafted input, leading to a frontend crash. The consequence of this vulnerability is a potential denial-of-service (DoS) attack. Users of these Mattermost versions are advised to upgrade to the latest, secure versions as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Mattermost Server
Affected Vendors
- Mattermost, Inc.