Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Update Mattermost Mobile Apps to versions 2.33.0 or higher.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Wed, 21 Jan 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:mattermost:mattermost_mobile:*:*:*:*:*:*:*:* |
Fri, 14 Nov 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost Mattermost mattermost Mobile |
|
| Vendors & Products |
Mattermost
Mattermost mattermost Mattermost mattermost Mobile |
Thu, 13 Nov 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Nov 2025 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the trusted server, which allows a malicious Mattermost instance or on-path attacker to obtain user session credentials via crafted token-in-URL responses | |
| Title | Inadequate validation of SSO redirect credentials permits credential theft | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-11-13T18:02:26.585Z
Reserved: 2025-10-15T11:16:32.195Z
Link: CVE-2025-59480
Updated: 2025-11-13T18:02:21.964Z
Status : Analyzed
Published: 2025-11-13T18:15:50.703
Modified: 2026-01-21T19:37:37.203
Link: CVE-2025-59480
No data.
OpenCVE Enrichment
Updated: 2025-11-14T09:28:06Z