No analysis available yet.
Vendor Solution
Update Mattermost to versions 10.6.0, 10.4.3, 10.5.1, 9.11.11 or higher. Otherwise, update the Playbooks plugin to version 2.1.1 or higher
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12104 | Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by the RetrospectivePost custom post type in the Playbooks plugin, which allows an attacker to create a specially crafted post with maliciously crafted props and cause a denial of service (DoS) of the web app for all users. |
Github GHSA |
GHSA-3g36-gf7c-75qw | Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type |
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Wed, 01 Oct 2025 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost mattermost Server
|
|
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost mattermost Server
|
Thu, 24 Apr 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 24 Apr 2025 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by the RetrospectivePost custom post type in the Playbooks plugin, which allows an attacker to create a specially crafted post with maliciously crafted props and cause a denial of service (DoS) of the web app for all users. | |
| Title | Webapp DoS via malicious retrospective post in Playbooks | |
| Weaknesses | CWE-1287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-04-24T13:58:04.968Z
Reserved: 2025-04-22T11:38:20.753Z
Link: CVE-2025-41395
Updated: 2025-04-24T13:57:59.781Z
Status : Analyzed
Published: 2025-04-24T07:15:31.600
Modified: 2025-10-01T19:35:27.030
Link: CVE-2025-41395
No data.
OpenCVE Enrichment
Updated: 2025-06-23T19:31:59Z
EUVD
Github GHSA