cbcvebase.
CVE-2025-13870
published 2025-12-02

CVE-2025-13870: Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards…

medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
Mattermost versions 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to validate the user permission when accessing the files and subscribing to the block in Boards, which allows an authenticated user to access other board files and was able to subscribe to the block from other boards that the user does not have access to

Affected

10 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost>= 10.11.0 < 10.11.510.11.5
github.commattermost_mattermost>= 10.11.0+incompatible < 10.11.5+incompatible10.11.5+incompatible
github.commattermost_mattermost>= 10.5.0 < 10.5.1310.5.13
github.commattermost_mattermost>= 10.5.0+incompatible < 10.5.13+incompatible10.5.13+incompatible
github.commattermost_mattermost_server_v8>= 0 < 8.0.0-20250905150616-ba86dfc5876b8.0.0-20250905150616-ba86dfc5876b
github.commattermost_mattermost_server_v8>= 0 < 8.0.0-20251212204551-54f2e9b4afd58.0.0-20251212204551-54f2e9b4afd5
mattermostmattermost10.11.0 – 10.11.4
mattermostmattermost10.5.0 – 10.5.12
mattermostmattermost_server>= 10.11.0 < 10.11.510.11.5
mattermostmattermost_server>= 10.5.0 < 10.5.1310.5.13