cve/2025/CVE-2025-2571.md
2025-09-29 21:09:30 +02:00

1.1 KiB

CVE-2025-2571

Description

Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth credentials when converting user accounts to bot accounts, allowing attackers to gain unauthorized access to bot accounts via the Google OAuth signup flow.

POC

Reference

Github

No PoCs found on GitHub currently.