CVE-2025-41410: Slack import bypasses email verification for team access controls
Mattermost versions 10.10.x <= 10.10.2, 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to validate email ownership during Slack import process which allows attackers to create verified user accounts with arbitrary email domains via malicious Slack import data to bypass email-based team access restrictions
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41410?
CVE-2025-41410 is rated as a high severity vulnerability due to its potential to allow unauthorized user account creation.
How do I fix CVE-2025-41410?
To fix CVE-2025-41410, upgrade to Mattermost versions 10.10.3, 10.5.11, or 10.11.3 or later.
What versions of Mattermost are affected by CVE-2025-41410?
CVE-2025-41410 affects Mattermost versions 10.10.x up to 10.10.2, 10.5.x up to 10.5.10, and 10.11.x up to 10.11.2.
What impact does CVE-2025-41410 have on Mattermost users?
CVE-2025-41410 allows attackers to bypass email verification and create user accounts with any email domain.
Is there a workaround for CVE-2025-41410?
There are no specific workarounds for CVE-2025-41410, so updating to the latest version is recommended.