Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to to verify that the token used during the code exchange originates from the same authentication flow, which allows an authenticated user to perform account takeover via a specially crafted email address used when switching authentication methods and sending a request to the /users/login/sso/code-exchange endpoint. The vulnerability requires ExperimentalEnableAuthenticationTransfer to be enabled (default: enabled) and RequireEmailVerification to be disabled (default: disabled).
We have discovered 62 live websites that are affected by CVE-2025-12421.
| Product | |
| Category | Message Boards |
| Vulnerable Domains | 62 live websites (15% of Mattermost install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 10 versions ( 15% of all versions) |
| 13 websites | |
| 23 websites | |
| 9 websites | |
| 3 websites | |
| 2 websites | |
| 2 websites | |
| 2 websites | |
| 1 websites | |
| 1 websites |
| .org | 14 websites |
| .com | 13 websites |
| .de | 11 websites |
| .ru | 4 websites |
| .co.uk | 2 websites |
| .fr | 2 websites |
| .info | 2 websites |
| .net | 2 websites |
| .io | 1 websites |
| .pl | 1 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********.com | ***,*** | ||
| ****.*******.com | ***,*** | ||
| ****.*******.org | *,***,*** | ||
| ***********.ru | *,***,*** | ||
| ****.*******.com | *,***,*** | ||
| ****.*********.org | *,***,*** | ||
| ****.**************.de | *,***,*** | ||
| *****.*************.org | *,***,*** | ||
| *******.org | *,***,*** | ||
| ******.*************.org | **,***,*** |
FAQ