CVE-2025-2571

Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth credentials when converting user accounts to bot accounts, allowing attackers to gain unauthorized access to bot accounts via the Google OAuth signup flow.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.2 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
MattermostCNA
4.2 MEDIUM
NETWORK
HIGH
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 18%
VendorProductVersion
mattermostmattermost_server
9.11.0 ≤
𝑥
< 9.11.13
mattermostmattermost_server
10.5.0 ≤
𝑥
< 10.5.4
mattermostmattermost_server
10.6.0 ≤
𝑥
< 10.6.3
mattermostmattermost_server
10.7.0 ≤
𝑥
< 10.7.1
𝑥
= Vulnerable software versions