CVE-2025-27936: Webhook Secret Exposure via Timing attack in MSteams plugin
Mattermost Plugin MSTeams versions <2.1.0 and Mattermost Server versions 10.5.x <=10.5.1 with the MS Teams plugin enabled fail to perform constant time comparison on a MSTeams plugin webhook secret which allows an attacker to retrieve the webhook secret of the MSTeams plugin via a timing attack during webhook secret comparison.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27936?
CVE-2025-27936 is rated as a high severity vulnerability due to its potential to expose sensitive webhook secrets.
How do I fix CVE-2025-27936?
To fix CVE-2025-27936, update the Mattermost Plugin MSTeams to version 2.1.0 or later and ensure that the Mattermost Server is upgraded to version 10.5.1 or later.
Which versions are affected by CVE-2025-27936?
CVE-2025-27936 affects Mattermost Plugin MSTeams versions prior to 2.1.0 and Mattermost Server versions 10.5.0 to 10.5.1.
What type of attack does CVE-2025-27936 facilitate?
CVE-2025-27936 may allow attackers to retrieve the webhook secret through a timing attack due to non-constant time comparison.
Is there a workaround for CVE-2025-27936 until I can update?
Currently, there are no documented workarounds for CVE-2025-27936; updating to the latest version is the recommended action.