Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Mattermost to versions 10.3.0, 2.23.0, 10.2.1, 9.11.6, 10.0.4, 10.1.4 or higher.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-0091 | Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post. |
Github GHSA |
GHSA-5m7j-6gc4-ff5g | Mattermost fails to properly validate post props |
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Tue, 30 Sep 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost mattermost Server
|
|
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.2.0:-:*:*:*:*:*:* |
|
| Vendors & Products |
Mattermost mattermost Server
|
Wed, 12 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 15 Jan 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate post props which allows a malicious authenticated user to cause a crash via a malicious post. | |
| Title | Insufficient Input Validation on Post Props | |
| Weaknesses | CWE-1287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-02-12T20:31:20.302Z
Reserved: 2025-01-14T00:19:35.055Z
Link: CVE-2025-20086
Updated: 2025-02-12T20:25:53.058Z
Status : Analyzed
Published: 2025-01-15T17:15:19.107
Modified: 2025-09-30T15:51:23.113
Link: CVE-2025-20086
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:26:24Z
EUVD
Github GHSA