CVE-2025-9084: Mattermost Server
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Mattermost versions 10.5.x <= 10.5.9 fail to properly validate redirect URLs which allows attackers to redirect users to malicious sites via crafted OAuth login URLs
Affected products
- Mattermost Mattermost Server: from 10.5.0, before 10.5.10 (fixed in 10.5.10)
Published 2025-09-15. Last modified 2026-06-17.