CWE
704
EPSS
0.043%
Advisory Published
Updated

CVE-2025-20072: Mobile crash via improper validation of proto style in attachments

First published: Thu Jan 16 2025(Updated: )

Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an action's style in post.props.attachments, which allows an attacker to crash the mobile via crafted malicious input.

Credit: responsibledisclosure@mattermost.com

Affected SoftwareAffected VersionHow to fix
Mattermost<=2.22.0

Remedy

Update Mattermost to versions 10.3.0, 2.23.0, 10.2.1, 9.11.6, 10.0.4, 10.1.4 or higher.

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2025-20072?

    CVE-2025-20072 is categorized as a high severity vulnerability due to its potential to crash the Mattermost Mobile application.

  • How do I fix CVE-2025-20072?

    To fix CVE-2025-20072, update Mattermost Mobile to version 2.22.1 or higher.

  • What types of devices are affected by CVE-2025-20072?

    CVE-2025-20072 affects Mattermost Mobile applications on Android devices running version 2.22.0 or earlier.

  • What does CVE-2025-20072 exploit?

    CVE-2025-20072 exploits improper validation of action style in post properties, allowing attackers to crash the application.

  • Is there a known workaround for CVE-2025-20072?

    There is no specific workaround for CVE-2025-20072; updating to a secure version is the recommended solution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203