Link Metadata Vulnerability in Mattermost by Mattermost
CVE-2025-9078
4.3MEDIUM
What is CVE-2025-9078?
The Mattermost platform contains a significant vulnerability linked to improper validation of cache keys for link metadata. This issue affects multiple versions of Mattermost, allowing authenticated users to exploit the situation by accessing unauthorized posts through hash collision attacks on the FNV-1 hashing algorithm. As a result, attackers can manipulate link previews, leading to potential misinformation or access to sensitive content. It is crucial for users running affected versions to apply the latest security updates from the Mattermost security updates page.
Affected Version(s)
Mattermost 10.8.0 <= 10.8.3
Mattermost 10.5.0 <= 10.5.8
Mattermost 9.11.0 <= 9.11.17