CVE-2025-6227
published 2025-07-18CVE-2025-6227: Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which allows a user that intercepts both invite…
PriorityP414low3.1CVSS 3.1
AVNACHPRLUINSUCNILAN
EPSS
0.18%
7.3th percentile
Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which allows a user that intercepts both invite and password to send synchronization payloads to the server that originally created the invite via the REST API.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| github.com | mattermost_mattermost-server | >= 10.5.0 < 10.5.8 | 10.5.8 |
| github.com | mattermost_mattermost-server | >= 10.5.0+incompatible < 10.5.8+incompatible | 10.5.8+incompatible |
| github.com | mattermost_mattermost-server | >= 9.11.0 < 9.11.17 | 9.11.17 |
| github.com | mattermost_mattermost-server | >= 9.11.0+incompatible < 9.11.17+incompatible | 9.11.17+incompatible |
| github.com | mattermost_mattermost_server_v8 | >= 0 < 8.0.0-20250612074655-8f8612c63783 | 8.0.0-20250612074655-8f8612c63783 |
| mattermost | mattermost | 10.5.0 – 10.5.7 | — |
| mattermost | mattermost | 9.11.0 – 9.11.16 | — |
| mattermost | mattermost_server | >= 10.5.0 < 10.5.8 | 10.5.8 |
| mattermost | mattermost_server | >= 9.11.0 < 9.11.17 | 9.11.17 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Mattermost has Insufficiently Protected Credentials in github.com/mattermost/mattermost-server
osv·2025-07-29
CVE-2025-6227 Mattermost has Insufficiently Protected Credentials in github.com/mattermost/mattermost-server
Mattermost has Insufficiently Protected Credentials in github.com/mattermost/mattermost-server
Mattermost has Insufficiently Protected Credentials in github.com/mattermost/mattermost-server
OSV
Mattermost has Insufficiently Protected Credentials
osv·2025-07-18
CVE-2025-6227 [LOW] Mattermost has Insufficiently Protected Credentials
Mattermost has Insufficiently Protected Credentials
Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which allows a user that intercepts both invite and password to send synchronization payloads to the server that originally created the invite via the REST API.
GHSA
Mattermost has Insufficiently Protected Credentials
ghsa·2025-07-18
CVE-2025-6227 [LOW] CWE-522 Mattermost has Insufficiently Protected Credentials
Mattermost has Insufficiently Protected Credentials
Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which allows a user that intercepts both invite and password to send synchronization payloads to the server that originally created the invite via the REST API.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-18
Published