CVE-2025-2091: M-Files Mobile
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
An open redirection vulnerability in M-Files mobile applications for Android and iOS prior to version 25.6.0 allows attackers to use maliciously crafted PDF files to trick other users into making requests to untrusted URLs.
Affected products
- M-Files M-Files Mobile: before 25.6.0 (fixed in 25.6.0)
Published 2025-06-16. Last modified 2026-06-17.