No analysis available yet.
Vendor Solution
Update Mattermost to versions 11.1.0, 11.0.5, 10.12.3, 10.11.7 or higher. Alternatively, update the Mattermost Calls plugin to version 1.11.0 or higher.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-gmx5-frv9-9m9f | Mattermost has CSRF vulnerability via Calls Widget page |
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
Mon, 29 Dec 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost mattermost Server
|
|
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost mattermost Server
|
Fri, 19 Dec 2025 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 17 Dec 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost
Mattermost mattermost |
|
| Vendors & Products |
Mattermost
Mattermost mattermost |
Wed, 17 Dec 2025 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls versions <=1.10.0 fail to implement CSRF protection on the Calls widget page which allows an authenticated attacker to initiate calls and inject messages into channels or direct messages via a malicious webpage or crafted link | |
| Title | CSRF Allows Call Initiation and Message Delivery | |
| Weaknesses | CWE-352 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2025-12-17T15:47:20.828Z
Reserved: 2025-11-17T09:59:16.331Z
Link: CVE-2025-62190
Updated: 2025-12-17T15:47:04.478Z
Status : Analyzed
Published: 2025-12-17T13:15:58.370
Modified: 2025-12-29T18:51:51.667
Link: CVE-2025-62190
No data.
OpenCVE Enrichment
Updated: 2025-12-17T21:18:42Z
Github GHSA