CVE-2025-9072: One-Click Mattermost Account Takeover via Poisoned RelayState SAML Parameter
Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirectto parameter, allowing an attacker to craft a malicious link that, once a user authenticates with their SAML provider, could post the user’s cookies to an attacker-controlled URL.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9072?
CVE-2025-9072 is considered a high severity vulnerability due to its potential to allow attackers to capture user cookies.
How do I fix CVE-2025-9072?
To fix CVE-2025-9072, update Mattermost to a version later than 10.10.1, 10.5.9, or 10.9.4.
What versions of Mattermost are affected by CVE-2025-9072?
Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, and 10.9.x <= 10.9.4 are affected by CVE-2025-9072.
What is the impact of CVE-2025-9072?
The impact of CVE-2025-9072 is that an attacker can craft a malicious link that can exfiltrate user cookies after SAML authentication.
Is there a workaround for CVE-2025-9072 if I cannot update?
There is no documented workaround for CVE-2025-9072, so the best course of action is to update to a secure version.