Launch Week Day 1: Announcing Security Design Review
MEDIUM 4.3 Go

Mattermost has CSRF vulnerability via Calls Widget page

GHSA-gmx5-frv9-9m9f · CVE-2025-62190 · GO-2025-4254

Published · Modified

Description

Mattermost versions 11.0.x < 11.0.4, 10.12.x <= 10.12.2, 10.11.x < 10.11.6 and Mattermost Calls versions < 1.10.0 fail to implement CSRF protection on the Calls widget page which allows an authenticated attacker to initiate calls and inject messages into channels or direct messages via a malicious webpage or crafted link.

Ready to move

Start Securing

Free, no credit card | First findings in minutes