CVE-2025-20072

Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the mobile via crafted malicious input.
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mattermost:mattermost_mobile:*:*:*:*:*:*:*:*

History

24 Sep 2025, 16:46

Type Values Removed Values Added
CPE cpe:2.3:a:mattermost:mattermost_mobile:*:*:*:*:*:*:*:*
Summary
  • (es) Las versiones de Mattermost Mobile &lt;= 2.22.0 no pueden validar correctamente el estilo del proto suministrado al estilo de una acción en post.props.attachments, lo que permite a un atacante bloquear el móvil a través de una entrada maliciosa manipulada.
References () https://mattermost.com/security-updates - () https://mattermost.com/security-updates - Vendor Advisory
First Time Mattermost mattermost Mobile
Mattermost

16 Jan 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-16 18:15

Updated : 2025-09-24 16:46


NVD link : CVE-2025-20072

Mitre link : CVE-2025-20072

CVE.ORG link : CVE-2025-20072


JSON object : View

Products Affected

mattermost

  • mattermost_mobile
CWE
CWE-704

Incorrect Type Conversion or Cast