CVE-2025-62190
vulnerability analysis and mitigation

Overview

CVE-2025-62190 is a Cross-Site Request Forgery (CSRF) vulnerability in Mattermost's Calls widget page that allows an authenticated attacker to initiate unauthorized calls and inject messages into channels or direct messages. It affects Mattermost Server versions 11.0.x ≤ 11.0.4, 10.12.x ≤ 10.12.2, and 10.11.x ≤ 10.11.6, as well as Mattermost Calls plugin versions ≤ 1.10.0. The vulnerability was published on December 17, 2025, and carries a CVSS v3.1 base score of 4.3 (Medium) (Mattermost Security, Red Hat CVE).

Technical details

The root cause is a failure to implement CSRF protection (CWE-352) on the Mattermost Calls widget page. Because the endpoint does not validate the origin of requests, an attacker can craft a malicious webpage or link that, when visited by an authenticated Mattermost user, silently submits forged requests on their behalf. This allows the attacker to trigger call initiations or inject messages into channels and direct messages without the victim's knowledge. No user privileges are required on the attacker's side; only the victim must be authenticated and interact with the malicious content (Mattermost Security, Red Hat CVE).

Impact

Successful exploitation allows an attacker to perform unauthorized actions on behalf of an authenticated Mattermost user, specifically initiating calls and injecting arbitrary messages into channels or direct messages. The integrity impact is limited — confidentiality and availability are not directly affected — but injected messages could be used for social engineering, phishing within the platform, or disruption of communications. The scope is limited to the affected Mattermost instance and does not provide a direct path to remote code execution or lateral movement (Mattermost Security).

Exploitation steps

  1. Reconnaissance: Identify a target organization using Mattermost with an affected version (11.0.x ≤ 11.0.4, 10.12.x ≤ 10.12.2, or 10.11.x ≤ 10.11.6) and the Calls plugin ≤ 1.10.0 enabled.
  2. Craft malicious page: Create a webpage or HTML email containing a hidden form or JavaScript that automatically submits a forged HTTP request to the Mattermost Calls widget endpoint (e.g., to initiate a call or post a message), targeting the victim's Mattermost session.
  3. Deliver the payload: Trick an authenticated Mattermost user into visiting the malicious page or clicking a crafted link — for example, via phishing email, social engineering, or embedding the link in an external communication.
  4. Trigger forged request: When the victim loads the page, the browser automatically sends the forged request with the victim's session cookies to the Mattermost server, which processes it as a legitimate action.
  5. Achieve objective: The attacker successfully initiates an unwanted call or injects a message into a channel or direct message on behalf of the victim, potentially enabling further social engineering or disruption (Mattermost Security).

Indicators of compromise

  • Logs: Mattermost server logs showing call initiation or message post events from a user's session originating from an unexpected or external referrer URL.
  • Network: HTTP requests to Mattermost Calls widget endpoints with a Referer header pointing to an external or unknown domain rather than the Mattermost instance itself.
  • Behavioral: Unexpected calls being initiated or messages appearing in channels/DMs that the user denies sending, particularly following a user clicking an external link.

Mitigation and workarounds

Mattermost has released patched versions addressing this vulnerability: update Mattermost Server to 11.0.5 or later, 10.12.3 or later, or 10.11.7 or later, and update the Mattermost Calls plugin to a version above 1.10.0. As interim measures, organizations should train users to avoid clicking unknown or unsolicited links, and consider deploying a Web Application Firewall (WAF) to detect and block anomalous cross-origin requests to Mattermost endpoints (Mattermost Security).

Community reactions

The vulnerability received routine coverage from vulnerability tracking services and security feeds shortly after disclosure in December 2025. Red Hat published a CVE advisory, and SUSE issued a related advisory in early 2026. No notable researcher commentary or significant community discussion has been identified beyond standard vulnerability database entries (Red Hat CVE).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management