CVE-2025-24839: Unauthorized AI bot activation via Wrangler plugin
Mattermost versions 10.5.x <= 10.5.1, 10.4.x <= 10.4.3, 9.11.x <= 9.11.9 fail to prevent Wrangler posts from triggering AI responses. This vulnerability allows users without access to the AI bot to activate it by attaching the activateai override property to a post via the Wrangler plugin, provided both the AI and Wrangler plugins are enabled.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-24839?
CVE-2025-24839 is considered a high-severity vulnerability as it allows unauthorized activation of AI responses.
How do I fix CVE-2025-24839?
To fix CVE-2025-24839, you should update Mattermost to the latest version, ensuring you are beyond versions 10.5.1, 10.4.3, and 9.11.9.
What are the affected versions in CVE-2025-24839?
CVE-2025-24839 affects Mattermost versions up to and including 10.5.1, 10.4.3, and 9.11.9.
What does CVE-2025-24839 allow attackers to do?
CVE-2025-24839 allows attackers to trigger AI responses without proper authorization through manipulated posts.
Is user access impacted by CVE-2025-24839?
Yes, CVE-2025-24839 affects user access by enabling unauthorized users to activate AI features.