CVE-2025-20072

Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the mobile via crafted malicious input.
References
Configurations

No configuration.

History

16 Jan 2025, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-16 18:15

Updated : 2025-01-16 18:15


NVD link : CVE-2025-20072

Mitre link : CVE-2025-20072

CVE.ORG link : CVE-2025-20072


JSON object : View

Products Affected

No product.

CWE
CWE-704

Incorrect Type Conversion or Cast