Mattermost Mobile Apps versions <=2.22.0 fail to properly handle specially crafted attachment names, which allows an attacker to crash the mobile app for any user who opened a channel containing the specially crafted attachment
{ "versions": [ { "introduced": "0" }, { "fixed": "2.23.0" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-0476.json"