Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Mattermost to versions 10.3.0, 2.23.0, 10.2.1, 9.11.6, 10.0.4, 10.1.4 or higher.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-0107 | Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the webapp to crash via creating and sending such a post to a channel. |
Github GHSA |
GHSA-w6xh-c82w-h997 | Mattermost webapp crash via a crafted post |
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Wed, 01 Oct 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost mattermost Server
|
|
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* cpe:2.3:a:mattermost:mattermost_server:10.2.0:-:*:*:*:*:*:* |
|
| Vendors & Products |
Mattermost mattermost Server
|
Thu, 16 Jan 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 16 Jan 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the webapp to crash via creating and sending such a post to a channel. | |
| Title | Webapp crash via object that can't be cast to String in Attachment Field | |
| Weaknesses | CWE-1287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-01-16T18:57:02.927Z
Reserved: 2025-01-16T18:10:41.926Z
Link: CVE-2025-20621
Updated: 2025-01-16T18:56:57.789Z
Status : Analyzed
Published: 2025-01-16T19:15:29.960
Modified: 2025-10-01T17:54:41.760
Link: CVE-2025-20621
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:07:19Z
EUVD
Github GHSA