CVE-2025-9072 Overview
CVE-2025-9072 is an open redirect vulnerability in Mattermost Server affecting the Security Assertion Markup Language (SAML) authentication flow. The server fails to validate the redirect_to parameter, allowing attackers to craft malicious authentication links. When a targeted user completes SAML authentication with their identity provider, the response containing session cookies is posted to an attacker-controlled URL. This flaw is tracked under CWE-601: URL Redirection to Untrusted Site and impacts multiple maintained release branches of Mattermost Server.
Critical Impact
Successful exploitation exposes authenticated user session cookies to attacker-controlled endpoints, enabling account takeover of any user coaxed into clicking a crafted SAML login link.
Affected Products
- Mattermost Server 10.10.x versions <= 10.10.1
- Mattermost Server 10.9.x versions <= 10.9.4
- Mattermost Server 10.5.x versions <= 10.5.9
Discovery Timeline
- 2025-09-15 - CVE-2025-9072 published to the National Vulnerability Database
- 2026-06-17 - Last updated in NVD database
Technical Details for CVE-2025-9072
Vulnerability Analysis
The vulnerability resides in Mattermost's SAML single sign-on handler. During authentication, the client supplies a redirect_to query parameter indicating the post-login destination. Mattermost stores that value and later uses it as the target for the SAML assertion response without validating that the destination belongs to the same origin or an allowed host.
An attacker distributes a crafted login URL to a legitimate Mattermost user. The victim authenticates normally with their SAML identity provider. The provider then submits the assertion, including session cookies bound to the response, to the URL specified by the attacker. Because the assertion is issued for a genuine session, the attacker gains material sufficient to hijack the user's authenticated context.
Root Cause
The root cause is missing allowlist validation of the redirect_to parameter. The application treats user-controlled input as a trusted post-authentication target. There is no check that the destination host matches the Mattermost site URL or an approved redirect list, which is the required mitigation for CWE-601.
Attack Vector
Exploitation requires network access to the Mattermost login endpoint and user interaction. The attacker sends a phishing message containing a URL pointing to the legitimate Mattermost host with a malicious redirect_to parameter appended. Because the initial hostname is authentic, standard link inspection does not flag the request. After the SAML handshake completes, the browser posts the response to the attacker's endpoint. See the Mattermost Security Updates advisory for vendor details.
Detection Methods for CVE-2025-9072
Indicators of Compromise
- Authentication requests to /login/sso/saml or related SAML endpoints containing redirect_to values pointing to external or unexpected hostnames.
- SAML assertion POST traffic from user browsers directed to hosts outside the organization's Mattermost domain.
- Successful logins immediately followed by session use from unfamiliar IP addresses or geolocations.
Detection Strategies
- Inspect web server and reverse proxy logs for SAML login URLs whose redirect_to parameter contains fully qualified external URLs.
- Correlate identity provider assertion logs with subsequent Mattermost session activity to identify assertions delivered to non-canonical endpoints.
- Alert on phishing emails or chat messages containing Mattermost login URLs with encoded external redirects.
Monitoring Recommendations
- Baseline the set of legitimate redirect_to destinations observed in production and alert on deviations.
- Enable identity provider logging for SAML response destinations and forward events to a centralized analytics platform.
- Monitor for anomalous session creation patterns, including simultaneous session use from disparate networks.
How to Mitigate CVE-2025-9072
Immediate Actions Required
- Upgrade Mattermost Server to a fixed release: 10.10.2 or later, 10.9.5 or later, or 10.5.10 or later on the respective branches.
- Invalidate active user sessions after patching to force reauthentication and revoke any cookies that may have been exposed.
- Review SAML identity provider logs for anomalous assertion destinations covering the exposure window prior to patching.
Patch Information
Mattermost has published corrected builds through the Mattermost Security Updates portal. Administrators should apply the vendor-supplied release corresponding to their deployment branch and restart the server to load the validation fix for the redirect_to parameter.
Workarounds
- Restrict egress from user workstations so browsers cannot post to arbitrary external endpoints where practical.
- Deploy a web application firewall rule that blocks SAML login requests whose redirect_to parameter references hostnames outside the Mattermost site URL.
- Educate users to avoid clicking Mattermost login links delivered through email or external channels until patching completes.
# Example WAF rule concept for blocking external redirect_to values
# Adjust for your WAF syntax and Mattermost site URL
SecRule ARGS:redirect_to "!@beginsWith https://mattermost.example.com" \
"id:1009072,phase:2,deny,status:400,msg:'CVE-2025-9072 external redirect_to blocked'"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.