CVE-2025-59480: Inadequate validation of SSO redirect credentials permits credential theft
Mattermost Mobile Apps versions <=2.32.0 fail to verify that SSO redirect tokens originate from the trusted server, which allows a malicious Mattermost instance or on-path attacker to obtain user session credentials via crafted token-in-URL responses
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59480?
CVE-2025-59480 is classified as a critical vulnerability due to the potential for unauthorized access to user session credentials.
How do I fix CVE-2025-59480?
To fix CVE-2025-59480, update the Mattermost Mobile Apps to a version greater than 2.32.0.
Who is affected by CVE-2025-59480?
Users of Mattermost Mobile Apps versions 2.32.0 and earlier are affected by CVE-2025-59480.
What type of vulnerability is CVE-2025-59480?
CVE-2025-59480 is an authentication and security misconfiguration vulnerability.
What could an attacker do with CVE-2025-59480?
An attacker could exploit CVE-2025-59480 to obtain user session credentials, allowing unauthorized access to user accounts.