cbcvebase.
CVE-2025-41423
published 2025-04-24

CVE-2025-41423: Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the API endpoint…

medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to properly validate permissions for the API endpoint /plugins/playbooks/api/v0/signal/keywords/ignore-thread, allowing any user or attacker to delete posts containing actions created by the Playbooks bot, even without channel access or appropriate permissions.

Affected

15 ranges
VendorProductVersion rangeFixed in
github.commattermost_mattermost-plugin-playbooks>= 0 < 1.41.01.41.0
github.commattermost_mattermost-plugin-playbooks>= 2.0.0
github.commattermost_mattermost-server>= 10.4.0+incompatible
github.commattermost_mattermost-server>= 10.5.0+incompatible
github.commattermost_mattermost-server>= 9.11.0+incompatible
github.commattermost_mattermost_server_v8>= 0 < 8.0.0-20250218121836-2b5275d871368.0.0-20250218121836-2b5275d87136
github.commattermost_mattermost_server_v8>= 10.4.0
github.commattermost_mattermost_server_v8>= 10.5.0
github.commattermost_mattermost_server_v8>= 9.11.0
mattermostmattermost
mattermostmattermost10.4.0 – 10.4.2
mattermostmattermost9.11.0 – 9.11.10
mattermostmattermost_server
mattermostmattermost_server>= 10.4.0 < 10.4.310.4.3
mattermostmattermost_server>= 9.11.0 < 9.11.119.11.11