Back

MEDIUM

Open redirection in M-Files Mobile

Published Jun 16, 2025

Description

An open redirection vulnerability in M-Files mobile applications for Android and iOS prior to version 25.6.0 allows attackers to use maliciously crafted PDF files to trick other users into making requests to untrusted URLs.

Affected products

Remediation

Vendor solution

Update M-Files Mobile to version 25.6.0 or newer.

Metrics

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner M-Files Corporation
Published Jun 16, 2025
Updated Feb 23, 2026
Reserved Mar 7, 2025
CISA Vulnrichment
Updated Jun 16, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a