Vulnerability Details CVE-2025-21088
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the frontend via crafted malicious input.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 45.1%
CVSS Severity
CVSS v3 Score 6.5
Products affected by CVE-2025-21088
-
cpe:2.3:a:mattermost:mattermost_server:10.0.0
-
cpe:2.3:a:mattermost:mattermost_server:10.0.1
-
cpe:2.3:a:mattermost:mattermost_server:10.0.2
-
cpe:2.3:a:mattermost:mattermost_server:10.0.3
-
cpe:2.3:a:mattermost:mattermost_server:10.1.0
-
cpe:2.3:a:mattermost:mattermost_server:10.1.1
-
cpe:2.3:a:mattermost:mattermost_server:10.1.2
-
cpe:2.3:a:mattermost:mattermost_server:10.1.3
-
cpe:2.3:a:mattermost:mattermost_server:10.2.0
-
cpe:2.3:a:mattermost:mattermost_server:9.11.0
-
cpe:2.3:a:mattermost:mattermost_server:9.11.1
-
cpe:2.3:a:mattermost:mattermost_server:9.11.2
-
cpe:2.3:a:mattermost:mattermost_server:9.11.3
-
cpe:2.3:a:mattermost:mattermost_server:9.11.4
-
cpe:2.3:a:mattermost:mattermost_server:9.11.5