CVE-2025-24839

CVSS 3.1 Score 3.1 of 10 (low)

Details

Published Apr 16, 2025
CWE ID 863

Summary

CVE-2025-24839 is a vulnerability affecting Mattermost versions 10.5.x up to 10.5.1, 10.4.x up to 10.4.3, and 9.11.x up to 9.11.9. This issue arises from the failure to prevent Wrangler posts from activating AI responses. Users who do not have access to the AI bot can exploit this by attaching the "activate_ai" override property to a post via the Wrangler plugin. Successful exploitation allows unauthorized activation of the AI bot.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Mattermost Server

Affected Vendors

  • Mattermost