CVE-2025-41395: Webapp DoS via malicious retrospective post in Playbooks
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by the RetrospectivePost custom post type in the Playbooks plugin, which allows an attacker to create a specially crafted post with maliciously crafted props and cause a denial of service (DoS) of the web app for all users.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41395?
CVE-2025-41395 has been classified as a high severity vulnerability due to its potential to allow attackers to exploit improperly validated props in the Mattermost Playbooks plugin.
How do I fix CVE-2025-41395?
To fix CVE-2025-41395, upgrade your Mattermost instance to versions 10.4.3, 10.5.1, or 9.11.11 or later.
Which versions are affected by CVE-2025-41395?
CVE-2025-41395 affects Mattermost versions 10.4.x up to and including 10.4.2, 10.5.x up to and including 10.5.0, and 9.11.x up to and including 9.11.10.
What type of attacks can be performed using CVE-2025-41395?
An attacker can exploit CVE-2025-41395 by creating specially crafted posts that can execute malicious actions within the Mattermost environment.
Is there a workaround for CVE-2025-41395?
No official workaround has been provided for CVE-2025-41395; users are advised to upgrade to fixed versions to mitigate risk.