CVE-2025-58073: Arbitrary Mattermost Team can be joined by manipulating the OAuth state
Mattermost versions 10.11.x <= 10.11.1, 10.10.x <= 10.10.2, 10.5.x <= 10.5.10 fail to verify a user has permission to join a Mattermost team using the original invite token which allows any attacked to join any team on a Mattermost server regardless of restrictions via manipulating the OAuth state.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58073?
The CVE-2025-58073 vulnerability is considered high severity due to its potential to allow unauthorized access to Mattermost teams.
How do I fix CVE-2025-58073?
To fix CVE-2025-58073, upgrade to Mattermost version 10.11.2, 10.10.3, or 10.5.11 or later.
Where is CVE-2025-58073 found?
CVE-2025-58073 is found in Mattermost versions 10.11.x up to 10.11.1, 10.10.x up to 10.10.2, and 10.5.x up to 10.5.10.
What does CVE-2025-58073 allow attackers to do?
CVE-2025-58073 allows attackers to join any Mattermost team by exploiting the original invite token without proper authorization.
Is CVE-2025-58073 easy to exploit?
Yes, CVE-2025-58073 can be exploited easily by manipulating the invite token, making it a significant security risk.