Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Mattermost to versions 10.3.0, 2.23.0, 10.2.1, 9.11.6, 10.0.4, 10.1.4 or higher.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-2148 | Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the mobile via crafted malicious input. |
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Wed, 24 Sep 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:mattermost:mattermost_mobile:*:*:*:*:*:*:*:* |
Thu, 16 Jan 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 16 Jan 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the mobile via crafted malicious input. | |
| Title | Mobile crash via improper validation of proto style in attachments | |
| Weaknesses | CWE-704 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-01-16T19:01:25.308Z
Reserved: 2025-01-15T15:30:33.457Z
Link: CVE-2025-20072
Updated: 2025-01-16T19:01:20.538Z
Status : Analyzed
Published: 2025-01-16T18:15:28.517
Modified: 2025-09-24T16:46:59.433
Link: CVE-2025-20072
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:07:21Z
EUVD