Back

HIGH

One-Click Mattermost Account Takeover via Poisoned RelayState SAML Parameter

Published Sep 15, 2025

Description

Mattermost versions 10.10.x <= 10.10.1, 10.5.x <= 10.5.9, 10.9.x <= 10.9.4 fail to validate the redirect_to parameter, allowing an attacker to craft a malicious link that, once a user authenticates with their SAML provider, could post the user’s cookies to an attacker-controlled URL.

Affected products

Remediation

Vendor solution

Update Mattermost to versions 10.11.0, 10.10.2, 10.5.10, 10.9.5 or higher.

Metrics

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Mattermost
Published Sep 15, 2025
Updated Sep 15, 2025
Reserved Aug 15, 2025
CISA Vulnrichment
Updated Sep 15, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-69J8-PRX2-VX98