CVE-2025-20621
MEDIUMDescription
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the webapp to crash via creating and sending such a post to a channel.
Is your site exposed to CVE-2025-20621?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| mattermost | mattermost_server |
| mattermost | mattermost_server |
| mattermost | mattermost_server |
| mattermost | mattermost_server |
References
Advisories & Patches
Frequently Asked Questions
What is CVE-2025-20621? +
How severe is CVE-2025-20621? +
What products are affected by CVE-2025-20621? +
How do I check if I'm vulnerable to CVE-2025-20621? +
Related Vulnerabilities
Improper Validation of Specified Type of Input vulnerability in ash-project ash lets an attacker confuse the stored type tag of …
Synapse is an open source Matrix homeserver implementation. Lack of validation for device keys in Synapse before 1.138.3 and in …
`_nx_icmpv6_validate_options()` scans the option area with `while (length > 2)` (`common/src/nx_icmpv6_validate_options.c:79`). An area whose size leaves a one- or two-byte …
github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not validate that a scalar variable value matches its declared type. The built-in …
A security issue exists due to improper handling of CIP Class 32’s request when a module is inhibited on the …
A security issue exists due to improper handling of CIP Class 32’s request when a module is inhibited on the …