Impact
The vulnerability arises from Mattermost’s failure to properly validate dynamic client registration redirect URIs. Instead of parsing the URL, the system matches glob patterns against the entire raw string. This flaw allows an attacker to craft a redirect URI that embeds an allowlisted host or path suffix within the query string, thereby bypassing the configured redirect URI allowlist. A remote and unauthenticated attacker can use this to register an OAuth client with a malicious callback host, potentially intercepting authorization codes or tokens.
Affected Systems
Mattermost deployments running versions 11.9.x (<=11.9.0), 11.8.x (<=11.8.4), or 11.7.x (<=11.7.7) are susceptible. The affected product is the Mattermost server component as documented by the Mattermost CNA. The official fix is available by upgrading to any of the following minimum versions: 11.10.0, 11.9.1, 11.8.5, or 11.7.8, which correct the redirect URI validation logic.
Risk and Exploitability
The CVSS score of 6.8 classifies this issue as moderate severity. There is currently no EPSS data, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is straightforward: an unauthenticated client can send a crafted registration request to the DCR endpoint, bypass the allowlist, and register a hostile OAuth client. Because the endpoint is publicly reachable and no authentication is required, the likelihood of exploitation is considered significant in environments with exposed Mattermost APIs.
OpenCVE Enrichment