CVE Vulnerabilities

CVE-2025-20072

Incorrect Type Conversion or Cast

Published: Jan 16, 2025 | Modified: Sep 24, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Mattermost Mobile versions <= 2.22.0 fail to properly validate the style of proto supplied to an actions style in post.props.attachments, which allows an attacker to crash the mobile via crafted malicious input.

Weakness

The product does not correctly convert an object, resource, or structure from one type to a different type.

Affected Software

Name Vendor Start Version End Version
Mattermost_mobile Mattermost * 2.23.0 (excluding)

References