CVE-2025-12421: Account Takeover via Code Exchange Endpoint
Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods and sending a request to the /users/login/sso/code-exchange endpoint. The vulnerability requires ExperimentalEnableAuthenticationTransfer to be enabled (default: enabled) and RequireEmailVerification to be disabled (default: disabled).
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12421?
CVE-2025-12421 is rated as a critical severity vulnerability due to its potential for account takeover.
How do I fix CVE-2025-12421?
To fix CVE-2025-12421, upgrade Mattermost to versions 10.5.13, 10.11.5, 10.12.2, or 11.0.3 or later.
What versions of Mattermost are affected by CVE-2025-12421?
CVE-2025-12421 affects Mattermost versions 11.0.2 and earlier, 10.12.1 and earlier, 10.11.4 and earlier, and 10.5.12 and earlier.
What type of attack can CVE-2025-12421 enable?
CVE-2025-12421 can enable an authenticated user to perform an account takeover.
Is there a public disclosure for CVE-2025-12421?
Yes, CVE-2025-12421 has been publicly disclosed as part of Mattermost's security updates.