CVE-2025-20072

Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the mobile via crafted malicious input.
References
Link Resource
https://mattermost.com/security-updates Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:mattermost:mattermost_mobile:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-01-16 18:15

Updated : 2025-09-24 16:46


NVD link : CVE-2025-20072

Mitre link : CVE-2025-20072

CVE.ORG link : CVE-2025-20072


JSON object : View

Products Affected

mattermost

  • mattermost_mobile
CWE
CWE-704

Incorrect Type Conversion or Cast