CVE-2025-13352
published 2025-12-17CVE-2025-13352: Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows…
PriorityP415low3CVSS 3.1
AVNACHPRLUIRSCCNILAN
EPSS
0.15%
4.4th percentile
Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack the GitHub reaction feature to make users add reactions to arbitrary GitHub objects via crafted notification posts.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost | >= 0 < 10.11.7-0.20251106103514-3b05384dd014 | 10.11.7-0.20251106103514-3b05384dd014 |
| github.com | mattermost_mattermost | >= 11.0.0-alpha.1 < 11.1.0 | 11.1.0 |
| github.com | mattermost_mattermost | >= 11.0.0-alpha.1+incompatible < 11.1.0+incompatible | 11.1.0+incompatible |
| github.com | mattermost_mattermost-plugin-github | >= 0 < 1.0.1-0.20250829075715-0deffcfc6bee | 1.0.1-0.20250829075715-0deffcfc6bee |
| github.com | mattermost_mattermost-server | >= 10.11.0-rc1+incompatible | — |
| github.com | mattermost_mattermost_server_v8 | >= 10.11.0-rc1 < 10.11.7-0.20251106103514-3b05384dd014 | 10.11.7-0.20251106103514-3b05384dd014 |
| mattermost | mattermost | 10.11.0 – 10.11.6 | — |
| mattermost | mattermost_server | >= 10.11.0 < 10.11.7 | 10.11.7 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost
osv·2025-12-22
CVE-2025-13352 Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014.
OSV
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection
osv·2025-12-17
CVE-2025-13352 [LOW] Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection
Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack the GitHub reaction feature to make users add reactions to arbitrary GitHub objects via crafted notification posts.
GHSA
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection
ghsa·2025-12-17
CVE-2025-13352 [LOW] CWE-1287 Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection
Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack the GitHub reaction feature to make users add reactions to arbitrary GitHub objects via crafted notification posts.
No detection rules found.
No public exploits indexed.
2025-12-17
Published