Loading...
Skip to main content

CVE-2025-12419

CRITICAL

Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication

Published November 27, 2025Updated December 17, 2025Source: osv

Summary

Mattermost versions 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12, 11.0.x <= 11.0.3 fail to properly validate OAuth state tokens during OpenID Connect authentication which allows an authenticated attacker with team creation privileges to take over a user account via manipulation of authentication data during the OAuth completion flow. This requires email verification to be disabled (default: disabled), OAuth/OpenID Connect to be enabled, and the attacker to control two users in the SSO system with one of them never having logged into Mattermost.

Remediation

Upgrade to the fixed version using your package manager.

Go
Update github.com/mattermost/mattermost-server to 11.0.4 or later
go get github.com/mattermost/mattermost-server@v11.0.4
Go
Update github.com/mattermost/mattermost-server to 10.12.2 or later
go get github.com/mattermost/mattermost-server@v10.12.2
Go
Update github.com/mattermost/mattermost-server to 10.11.5 or later
go get github.com/mattermost/mattermost-server@v10.11.5
Go
Update github.com/mattermost/mattermost-server to 10.5.13 or later
go get github.com/mattermost/mattermost-server@v10.5.13
Go
Update github.com/mattermost/mattermost/server/v8 to 8.0.0-20251028000919-d3ed703dc833 or later
go get github.com/mattermost/mattermost/server/v8@v8.0.0-20251028000919-d3ed703dc833

After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.

Affected Packages (5)

PackageEcosystemAffectedFixed In
github.com/mattermost/mattermost-server
go
All versions11.0.4
github.com/mattermost/mattermost-server
go
All versions10.12.2
github.com/mattermost/mattermost-server
go
All versions10.11.5
github.com/mattermost/mattermost-server
go
All versions10.5.13
github.com/mattermost/mattermost/server/v8
go
All versions8.0.0-20251028000919-d3ed703dc833

Vulnerability Classification

Common Weakness Enumeration (CWE) identifiers for this vulnerability type.

CVSS Score Breakdown

What the CVSS (Common Vulnerability Scoring System) 9.9 score means for each attack dimension.

Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Frequently Asked Questions

What is CVE-2025-12419?
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication This vulnerability has been assigned a severity rating of CRITICAL (CVSS score: 9.9/10).
How do I check if my project is affected by CVE-2025-12419?
CVE-2025-12419 affects github.com/mattermost/mattermost-server and github.com/mattermost/mattermost/server/v8. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2025-12419 and 200,000+ other known vulnerabilities.

Severity & Exploitability

CVSS Score
9.9

Exploitation is straightforward and causes maximum impact. Patch immediately.

Also Known As

GHSA-3x39-62h4-f8j6
GO-2025-4168

Related CVEs

Check if you're affected

Scan your dependencies to see if this vulnerability affects your projects.

Scan Your Dependencies