cbcvebase.
CVE-2025-11777
published 2025-11-13

CVE-2025-11777: Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API which allows…

medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API which allows users from one team to access user metadata and channel membership information from other teams via the API endpoint

Affected

14 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost>= 0 < 5.3.2-0.20250905150616-ba86dfc5876b5.3.2-0.20250905150616-ba86dfc5876b
github.commattermost_mattermost-server>= 0 < 5.3.2-0.20250905150616-ba86dfc5876b5.3.2-0.20250905150616-ba86dfc5876b
github.commattermost_mattermost-server>= 10.11.0 < 10.11.410.11.4
github.commattermost_mattermost-server>= 10.11.0+incompatible < 10.11.4+incompatible10.11.4+incompatible
github.commattermost_mattermost-server>= 10.5.0 < 10.5.1210.5.12
github.commattermost_mattermost-server>= 10.5.0+incompatible < 10.5.12+incompatible10.5.12+incompatible
github.commattermost_mattermost-server_v5>= 0 < 5.3.2-0.20250905150616-ba86dfc5876b5.3.2-0.20250905150616-ba86dfc5876b
github.commattermost_mattermost-server_v6>= 0 < 5.3.2-0.20250905150616-ba86dfc5876b5.3.2-0.20250905150616-ba86dfc5876b
github.commattermost_mattermost_server_v8>= 0 < 8.0.0-20251212204551-54f2e9b4afd58.0.0-20251212204551-54f2e9b4afd5
github.commattermost_mattermost_server_v8>= 0 < 8.0.0-20250905150616-ba86dfc5876b8.0.0-20250905150616-ba86dfc5876b
mattermostmattermost10.11.0 – 10.11.3
mattermostmattermost10.5.0 – 10.5.11
mattermostmattermost_server>= 10.11.0 < 10.11.410.11.4
mattermostmattermost_server>= 10.5.0 < 10.5.1210.5.12