Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate the props used by the RetrospectivePost custom post type in the Playbooks plugin, which allows an attacker to create a specially crafted post with maliciously crafted props and cause a denial of service (DoS) of the web app for all users.
{
"github_reviewed": true,
"nvd_published_at": "2025-04-24T07:15:31Z",
"severity": "MODERATE",
"cwe_ids": [
"CWE-1287"
],
"github_reviewed_at": "2025-04-24T16:09:27Z"
}