An issue was discovered in Mattermost Server before 4.5.0, 4.4.5, 4.3.4, and 4.2.2. It allows attackers to cause a denial of service (application crash) via an @ character before a JavaScript field name.
{
"severity": "HIGH",
"github_reviewed_at": "2025-12-03T19:29:16Z",
"cwe_ids": [
"CWE-248"
],
"nvd_published_at": "2020-06-19T17:15:00Z",
"github_reviewed": true
}