Security Flaw in Mattermost Affects Multiple Versions
CVE-2025-9072
7.6HIGH
What is CVE-2025-9072?
In Mattermost versions 10.10.x up to 10.10.1, 10.5.x up to 10.5.9, and 10.9.x up to 10.9.4, a security weakness exists in the validation of the redirect_to parameter. This oversight permits attackers to craft malicious links that may redirect users post-authentication with their SAML provider, enabling the potential exposure of user cookies to attacker-controlled sites.
Affected Version(s)
Mattermost 10.10.0 <= 10.10.1
Mattermost 10.5.0 <= 10.5.9
Mattermost 10.9.0 <= 10.9.4