CVE-2025-62690: Open redirect in error page when link opened in new tab
Mattermost versions 10.11.x <= 10.11.4 fail to validate redirect URLs on the /error page, which allows an attacker to redirect a victim to a malicious site via a crafted link opened in a new tab.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62690?
The severity of CVE-2025-62690 is considered high due to the risk of redirection to malicious sites.
How do I fix CVE-2025-62690?
To fix CVE-2025-62690, upgrade Mattermost to version 10.11.5 or later to ensure proper validation of redirect URLs.
What versions of Mattermost are affected by CVE-2025-62690?
Mattermost versions 10.11.x up to and including 10.11.4 are affected by CVE-2025-62690.
What is the impact of CVE-2025-62690 on users?
CVE-2025-62690 allows attackers to redirect users to potentially harmful websites, compromising user security.
Can I mitigate CVE-2025-62690 without an update?
While the best mitigation is updating to a secure version, you can restrict access to the /error page or review installed applications for potential threats until you can update.