WebApp crash via improper validation of proto style in attachments
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the frontend via crafted malicious input.
02 / AFFECTED SOFTWARE
Affected packages
45 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the frontend via crafted malicious input.
Mattermost Incorrect Type Conversion or Cast in github.com/mattermost/mattermost-server
Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the frontend via crafted malicious input.
05 / REFERENCES
Further evidence
- https://github.com/mattermost/mattermost
- https://mattermost.com/security-updates
- https://nvd.nist.gov/vuln/detail/CVE-2025-21088
- https://pkg.go.dev/vuln/GO-2025-3393
- https://github.com/advisories/GHSA-8j3q-gc9x-7972
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/21xxx/CVE-2025-21088.json