CVE-2025-24839
CVSS 3.1 Score 3.1 of 10 (low)
Details
Published Apr 16, 2025
CWE ID 863
Summary
CVE-2025-24839 is a vulnerability affecting Mattermost versions 10.5.x up to 10.5.1, 10.4.x up to 10.4.3, and 9.11.x up to 9.11.9. This issue arises from the failure to prevent Wrangler posts from activating AI responses. Users who do not have access to the AI bot can exploit this by attaching the "activate_ai" override property to a post via the Wrangler plugin. Successful exploitation allows unauthorized activation of the AI bot.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Mattermost Server
Affected Vendors
- Mattermost