Mattermost versions 10.7.x <= 10.7.0, 10.6.x <= 10.6.2, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to clear Google OAuth credentials when converting user accounts to bot accounts, allowing attackers to gain unauthorized access to bot accounts via the Google OAuth signup flow.
We have discovered 54 live websites that are affected by CVE-2025-2571.
| Product | |
| Category | Message Boards |
| Vulnerable Domains | 54 live websites (13% of Mattermost install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 8 versions ( 12% of all versions) |
| 7 websites | |
| 9 websites | |
| 9 websites | |
| 8 websites | |
| 5 websites | |
| 3 websites | |
| 2 websites | |
| 2 websites | |
| 2 websites | |
| .ru | 18 websites |
| .org | 11 websites |
| .com | 5 websites |
| .de | 5 websites |
| .be | 1 websites |
| .fr | 1 websites |
| .net | 1 websites |
| .se | 1 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********.ru | *,***,*** | ||
| *****.*************.org | *,***,*** | ||
| *******************.com | **,***,*** | ||
| ******.*************.org | **,***,*** | ||
| *****.****.to | **,***,*** | ||
| ****.************.se | **,***,*** | ||
| *******.*************.org | **,***,*** | ||
| **.********.com | **,***,*** | ||
| ****.*************.fm | **,***,*** | ||
| *****.****.ru | **,***,*** |
FAQ