CVE-2025-41395

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 24, 2025
Updated: Apr 29, 2025
CWE ID 1287

Summary

CVE-2025-41395 is a vulnerability affecting Mattermost versions 10.4.x up to 10.4.2, 10.5.x up to 10.5.0, and 9.11.x up to 9.11.10. This issue arises due to the failure of these versions to adequately validate the props utilized by the RetrospectivePost custom post type in the Playbooks plugin. Malicious actors can exploit this vulnerability by crafting a specifically designed post with manipulated props, thereby causing a Denial of Service (DoS) for all users on the web application.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share