/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2025-41395

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2025-41395

Severity

7.5

High

CVSS V3

Description

Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by the RetrospectivePost custom post type in the Playbooks plugin, which allows an attacker to create a specially crafted post with maliciously crafted props and cause a denial of service (DoS) of the web app for all users.

References

  • https://images.chainguard.dev/security/CGA-54r4-mqfg-4cf3

Affected packages


Safe Source for Open Source™
Contact us
© 2025 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing