Back

MEDIUM

Data exfiltration via AI plugin Jira tool

Published Apr 16, 2025

Description

Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.9 fail to restrict domains the LLM can request to contact upstream which allows an authenticated user to exfiltrate data from an arbitrary server accessible to the victim via performing a prompt injection in the AI plugin's Jira tool.

Affected products

Remediation

Vendor solution

Update Mattermost to versions 10.6.0, 10.4.3, 10.5.1, 9.11.10 or higher.

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Mattermost
Published Apr 16, 2025
Updated Apr 16, 2025
Reserved Apr 8, 2025
CISA Vulnrichment
Updated Apr 16, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Mattermost
Published Apr 16, 2025
Updated Apr 16, 2025
Exploited since n/a
EUVD-2025-11357 GHSA-9H6J-4FFX-CM84