
`Mattermost` (`CVE-2025-12419`) has an authentication bypass flaw via `OAuth` state token validation during `OpenID Connect`. Affects 10.12.1, 10.11.4, 10.5.12, 11.0.3. Patch advised. #Mattermost #AuthBypass #infosec https://www.pulsepatch.io/posts/cve-2025-12419-mattermost-oauth-validation-bypass
Post summary
A new authentication bypass flaw (CVE-2025-12419) in Mattermost's OpenID Connect implementation is disclosed, with impacted releases identified and a patch advised.
