CVE-2025-9084: Mattermost Server

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Mattermost versions 10.5.x <= 10.5.9 fail to properly validate redirect URLs which allows attackers to redirect users to malicious sites via crafted OAuth login URLs

Affected products

  • Mattermost Mattermost Server: from 10.5.0, before 10.5.10 (fixed in 10.5.10)

Published 2025-09-15. Last modified 2026-06-17.