PT-2025-12657 · Mattermost · Mattermost Mobile Apps

Defalt47

·

Published

2025-03-17

·

Updated

2025-03-24

·

CVE-2025-1558

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Mattermost Mobile Apps versions <=2.25.0
Description The issue is related to the improper validation of GIF images prior to rendering, which allows a malicious user to cause the Android application to crash via a message containing a maliciously crafted GIF.
Recommendations For Mattermost Mobile Apps versions <=2.25.0, update to a version greater than 2.25.0 to resolve the issue. As a temporary workaround, consider avoiding the use of GIF images in messages until a patch is available. Restrict access to untrusted messages to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-16008
CVE-2025-1558

Affected Products

Mattermost Mobile Apps