CVE-2025-13821: User profile update exposes password hash and MFA secrets
Mattermost versions 11.1.x <= 11.1.2, 10.11.x <= 10.11.9, 11.2.x <= 11.2.1 fail to sanitize sensitive data in WebSocket messages which allows authenticated users to exfiltrate password hashes and MFA secrets via profile nickname updates or email verification events. Mattermost Advisory ID: MMSA-2025-00560
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-13821?
CVE-2025-13821 has a high severity rating due to the exposure of sensitive information such as password hashes and MFA secrets.
How do I fix CVE-2025-13821?
To fix CVE-2025-13821, update Mattermost to versions 10.11.10 or higher, 11.1.3 or higher, or 11.2.2 or higher.
What types of data are exposed in CVE-2025-13821?
CVE-2025-13821 exposes password hashes and MFA secrets through unprocessed WebSocket messages.
In which Mattermost versions does CVE-2025-13821 exist?
CVE-2025-13821 affects Mattermost versions 11.1.x up to 11.1.2, 10.11.x up to 10.11.9, and 11.2.x up to 11.2.1.
Who is affected by CVE-2025-13821?
Authenticated users of the vulnerable Mattermost versions can potentially exfiltrate sensitive information if CVE-2025-13821 is present.