Home

Description

Mattermost Mobile Apps versions <=2.25.0 fail to terminate sessions during logout under certain conditions (e.g. poor connectivity), allowing unauthorized users on shared devices to access sensitive notification content via continued mobile notifications

PUBLISHED Reserved 2025-04-08 | Published 2025-04-14 | Updated 2025-04-14 | Assigner Mattermost




LOW: 2.0CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-613: Insufficient Session Expiration

Product status

Default status
unaffected

Any version
affected

2.26.0
unaffected

Credits

Elias Nahum finder

References

mattermost.com/security-updates

cve.org (CVE-2025-30516)

nvd.nist.gov (CVE-2025-30516)

Download JSON