PT-2025-51828 · Mattermost · Mattermost

Mario Puente

·

Published

2025-10-06

·

Updated

2026-01-17

·

CVE-2025-62690

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mattermost versions 10.11.0 through 10.11.4
Description The application does not properly validate redirect URLs on the /error page. This allows an attacker to redirect a victim to a malicious site by crafting a link that, when opened in a new tab, exploits this flaw. The vulnerable component is the handling of redirect URLs on the /error endpoint.
Recommendations Update to a version later than 10.11.4.

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

BDU:2025-16346
CVE-2025-62690
GHSA-Q66G-Q98C-Q454
GO-2025-4248
SUSE-SU-2026:0142-1

Affected Products

Mattermost