CVE-2025-31363: Data exfiltration via AI plugin Jira tool
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.9 fail to restrict domains the LLM can request to contact upstream which allows an authenticated user to exfiltrate data from an arbitrary server accessible to the victim via performing a prompt injection in the AI plugin's Jira tool.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-31363?
CVE-2025-31363 has been rated as a critical vulnerability due to its potential to allow data exfiltration.
How do I fix CVE-2025-31363?
To fix CVE-2025-31363, upgrade to Mattermost versions 10.5.1 or later, or 9.11.10 or later.
Who is affected by CVE-2025-31363?
CVE-2025-31363 affects Mattermost versions 10.4.2, 10.5.0, and 9.11.9.
What action should I take if I can't update to a safe version for CVE-2025-31363?
If unable to update, consider implementing stricter access controls and monitoring user activities until a patch can be applied.
What type of attack is associated with CVE-2025-31363?
CVE-2025-31363 is associated with prompt injection attacks that can lead to unauthorized data access.