
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62190 is a Cross-Site Request Forgery (CSRF) vulnerability in Mattermost's Calls widget page that allows an authenticated attacker to initiate unauthorized calls and inject messages into channels or direct messages. It affects Mattermost Server versions 11.0.x ≤ 11.0.4, 10.12.x ≤ 10.12.2, and 10.11.x ≤ 10.11.6, as well as Mattermost Calls plugin versions ≤ 1.10.0. The vulnerability was published on December 17, 2025, and carries a CVSS v3.1 base score of 4.3 (Medium) (Mattermost Security, Red Hat CVE).
The root cause is a failure to implement CSRF protection (CWE-352) on the Mattermost Calls widget page. Because the endpoint does not validate the origin of requests, an attacker can craft a malicious webpage or link that, when visited by an authenticated Mattermost user, silently submits forged requests on their behalf. This allows the attacker to trigger call initiations or inject messages into channels and direct messages without the victim's knowledge. No user privileges are required on the attacker's side; only the victim must be authenticated and interact with the malicious content (Mattermost Security, Red Hat CVE).
Successful exploitation allows an attacker to perform unauthorized actions on behalf of an authenticated Mattermost user, specifically initiating calls and injecting arbitrary messages into channels or direct messages. The integrity impact is limited — confidentiality and availability are not directly affected — but injected messages could be used for social engineering, phishing within the platform, or disruption of communications. The scope is limited to the affected Mattermost instance and does not provide a direct path to remote code execution or lateral movement (Mattermost Security).
Referer header pointing to an external or unknown domain rather than the Mattermost instance itself.Mattermost has released patched versions addressing this vulnerability: update Mattermost Server to 11.0.5 or later, 10.12.3 or later, or 10.11.7 or later, and update the Mattermost Calls plugin to a version above 1.10.0. As interim measures, organizations should train users to avoid clicking unknown or unsolicited links, and consider deploying a Web Application Firewall (WAF) to detect and block anomalous cross-origin requests to Mattermost endpoints (Mattermost Security).
The vulnerability received routine coverage from vulnerability tracking services and security feeds shortly after disclosure in December 2025. Red Hat published a CVE advisory, and SUSE issued a related advisory in early 2026. No notable researcher commentary or significant community discussion has been identified beyond standard vulnerability database entries (Red Hat CVE).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."