
A critical token validation bypass (CVE-2025-12421) affects `Mattermost` server. Authenticated users could perform unauthorized actions due to improper token origin verification during code exchange. #Mattermost #Infosec #AuthBypass https://www.pulsepatch.io/posts/cve-2025-12421-mattermost-server-token-validation-bypass
Post summary
The post announces a critical token validation bypass (CVE‑2025‑12421) in Mattermost, revealing that authenticated users can perform unauthorized actions due to improper token origin verification during code exchange.
