An open redirection vulnerability in M-Files mobile applications for Android and iOS prior to version 25.6.0 allows attackers to use maliciously crafted PDF files to trick other users into making requests to untrusted URLs.
Metrics
Affected Vendors & Products
References
History
Mon, 23 Feb 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 29 Oct 2025 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
M-files
M-files m-files Mobile |
|
| CPEs | cpe:2.3:a:m-files:m-files_mobile:*:*:*:*:*:android:*:* cpe:2.3:a:m-files:m-files_mobile:*:*:*:*:*:iphone_os:*:* |
|
| Vendors & Products |
M-files
M-files m-files Mobile |
|
| Metrics |
cvssV3_1
|
Mon, 16 Jun 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Jun 2025 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An open redirection vulnerability in M-Files mobile applications for Android and iOS prior to version 25.6.0 allows attackers to use maliciously crafted PDF files to trick other users into making requests to untrusted URLs. | |
| Title | Open redirection in M-Files Mobile | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: M-Files Corporation
Published: 2025-06-16T08:27:13.170Z
Updated: 2026-02-23T10:25:35.329Z
Reserved: 2025-03-07T11:57:54.664Z
Link: CVE-2025-2091
Updated: 2025-06-16T16:32:19.819Z
Status : Modified
Published: 2025-06-16T09:15:19.067
Modified: 2026-02-23T11:16:20.077
Link: CVE-2025-2091
No data.
ReportizFlow