Mattermost versions 10.2.x <= 10.2.0, 9.11.x <= 9.11.5, 10.0.x <= 10.0.3, 10.1.x <= 10.1.3 fail to properly handle posts with attachments containing fields that cannot be cast to a String, which allows an attacker to cause the webapp to crash via creating and sending such a post to a channel.
{
"nvd_published_at": "2025-01-16T19:15:29Z",
"cwe_ids": [
"CWE-1287"
],
"severity": "MODERATE",
"github_reviewed_at": "2025-01-16T23:09:09Z",
"github_reviewed": true
}