Github.Com Mattermost Mattermost-Server vulnerabilities

222 known vulnerabilities affecting github.com/mattermost_mattermost-server.

Total CVEs
222
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL10HIGH18MEDIUM100LOW22UNKNOWN72

Vulnerabilities

Page 4 of 12
CVE-2025-6233MEDIUM≥ 10.8.0, < 10.8.2≥ 10.7.0, < 10.7.4+2 more2025-07-18
CVE-2025-6233 [MEDIUM] CWE-22 Mattermost Path Traversal vulnerability Mattermost Path Traversal vulnerability Mattermost versions 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to sanitize input paths of file attachments in the bulk import JSONL file, which allows a system admin to read arbitrary system files via path traversal.
ghsaosv
CVE-2025-6226MEDIUM≥ 10.5.0, < 10.5.7≥ 10.8.0, < 10.8.2+2 more2025-07-18
CVE-2025-6226 [MEDIUM] CWE-306 Mattermost Missing Authentication for Critical Function Mattermost Missing Authentication for Critical Function Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts by PendingPostID which allows an authenticated user to read posts in private channels they don't have access to via guessing the PendingPostID of recently created posts.
ghsaosv
CVE-2025-6227LOW≥ 10.5.0, < 10.5.8≥ 9.11.0, < 9.11.172025-07-18
CVE-2025-6227 [LOW] CWE-522 Mattermost has Insufficiently Protected Credentials Mattermost has Insufficiently Protected Credentials Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which allows a user that intercepts both invite and password to send synchronization payloads to the server that originally created the invite via the REST API.
ghsaosv
CVE-2025-46702MEDIUM≥ 0, < 0.0.0-20250513065225-4ae5d647fb882025-06-30
CVE-2025-46702 [MEDIUM] CWE-863 Mattermost Incorrect Authorization vulnerability Mattermost Incorrect Authorization vulnerability Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions when adding participants to playbook runs. This allows authenticated users with member-level permissions to bypass system admin restrictions and add or remove users to/from private channels via th
ghsaosv
CVE-2025-47871MEDIUM≥ 0, < 0.0.0-20250513065225-4ae5d647fb882025-06-30
CVE-2025-47871 [MEDIUM] CWE-863 Mattermost Incorrect Authorization vulnerability Mattermost Incorrect Authorization vulnerability Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly validate channel membership when retrieving playbook run metadata, allowing authenticated users who are playbook members but not channel members to access sensitive information about linked private channels including channel name, display nam
ghsaosv
CVE-2025-4981CRITICAL≥ 0, < 0.0.0-20250519205859-65aec10162f62025-06-20
CVE-2025-4981 [CRITICAL] CWE-427 Mattermost allows authenticated users to write files to arbitrary locations Mattermost allows authenticated users to write files to arbitrary locations Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to sanitize filenames in the archive extractor which allows authenticated users to write files to arbitrary locations on the filesystem via uploading archives with path traversal sequences in filenam
ghsaosv
CVE-2025-3227MEDIUM≥ 0, < 0.0.0-20250520060012-d0380305ef7a2025-06-20
CVE-2025-3227 [MEDIUM] CWE-863 Mattermost allows unauthorized channel member management through playbook runs Mattermost allows unauthorized channel member management through playbook runs Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions in playbook runs, allowing authenticated users without the 'Manage Channel Members' permission to add or remove users from public and pri
ghsaosv
CVE-2025-3228MEDIUM≥ 0, < 0.0.0-20250520060012-d0380305ef7a2025-06-20
CVE-2025-3228 [MEDIUM] CWE-863 Mattermost allows an unauthorized Guest user access to Playbook Mattermost allows an unauthorized Guest user access to Playbook Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly retrieve requestorInfo from playbooks handler for guest users which allows an attacker access to the playbook run.
ghsaosv
CVE-2025-4573MEDIUM≥ 10.7.0, < 10.7.2≥ 10.6.0, < 10.6.4+2 more2025-06-11
CVE-2025-4573 [MEDIUM] CWE-90 Mattermost allows authenticated administrator to execute LDAP search filter injection Mattermost allows authenticated administrator to execute LDAP search filter injection Mattermost versions 10.7.x <= 10.7.1, 10.6.x <= 10.6.3, 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly validate LDAP group ID attributes, allowing an authenticated administrator with PermissionSysconsoleWriteUserManagementGroups permission to execute LDAP search filter injection via the PUT
ghsaosv
CVE-2025-4128LOW≥ 10.5.0, < 10.5.5≥ 9.11.0, < 9.11.142025-06-11
CVE-2025-4128 [LOW] CWE-863 Mattermost allows guest users to view information about public teams they are not members of Mattermost allows guest users to view information about public teams they are not members of Mattermost versions 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly restrict API access to team information, allowing guest users to bypass permissions and view information about public teams they are not members of via a direct API call to /api/v4/teams/{team_id}.
ghsaosv
CVE-2025-3913UNKNOWN≥ 9.0.0-rc1+incompatible, < 9.11.13+incompatible≥ 10.5.0-rc1+incompatible, < 10.5.4+incompatible+2 more2025-06-03
CVE-2025-3913 Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server
osv
CVE-2025-2571UNKNOWN≥ 9.0.0-rc1+incompatible, < 9.11.13+incompatible≥ 10.0.0-rc1+incompatible, < 10.5.4+incompatible+2 more2025-06-03
CVE-2025-2571 Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server
osv
CVE-2025-3611UNKNOWN≥ 9.0.0-rc1+incompatible, < 9.11.13+incompatible≥ 10.0.0-rc1+incompatible, < 10.5.4+incompatible+1 more2025-06-03
CVE-2025-3611 Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server
osv
CVE-2025-3230UNKNOWN≥ 9.0.0-rc1+incompatible, < 9.11.13+incompatible≥ 10.0.0-rc1+incompatible, < 10.5.4+incompatible+2 more2025-06-03
CVE-2025-3230 Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server
osv
CVE-2025-1792UNKNOWN≥ 9.0.0-rc1+incompatible, < 9.11.13+incompatible≥ 10.0.0-rc1+incompatible, < 10.5.4+incompatible+1 more2025-06-03
CVE-2025-1792 Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server
osv
CVE-2025-2527UNKNOWN≥ 9.11.0+incompatible, < 9.11.12+incompatible≥ 10.5.0+incompatible, < 10.5.3+incompatible2025-05-23
CVE-2025-2527 Mattermost Fails to Verify User's Permissions When Accessing Groups in github.com/mattermost/mattermost-server Mattermost Fails to Verify User's Permissions When Accessing Groups in github.com/mattermost/mattermost-server Mattermost Fails to Verify User's Permissions When Accessing Groups in github.com/mattermost/mattermost-server
osv
CVE-2025-2570UNKNOWN≥ 9.11.0+incompatible, < 9.11.12+incompatible≥ 10.5.0+incompatible, < 10.5.3+incompatible2025-05-23
CVE-2025-2570 Mattermost Fails to Check User Access to `ExperimentalSettings` in github.com/mattermost/mattermost-server Mattermost Fails to Check User Access to `ExperimentalSettings` in github.com/mattermost/mattermost-server Mattermost Fails to Check User Access to `ExperimentalSettings` in github.com/mattermost/mattermost-server
osv
CVE-2025-31947UNKNOWN≥ 9.11.0+incompatible, < 9.11.12+incompatible≥ 10.4.0+incompatible, < 10.4.5+incompatible+2 more2025-05-23
CVE-2025-31947 Mattermost Fails to Lockout LDAP Users After Repeated Login Failures in github.com/mattermost/mattermost-server Mattermost Fails to Lockout LDAP Users After Repeated Login Failures in github.com/mattermost/mattermost-server Mattermost Fails to Lockout LDAP Users After Repeated Login Failures in github.com/mattermost/mattermost-server
osv
CVE-2025-3446UNKNOWN≥ 9.11.0+incompatible, < 9.11.12+incompatible≥ 10.4.0+incompatible, < 10.4.5+incompatible+2 more2025-05-23
CVE-2025-3446 Mattermost Fails to Validate Team Invite Permissions in github.com/mattermost/mattermost-server Mattermost Fails to Validate Team Invite Permissions in github.com/mattermost/mattermost-server Mattermost Fails to Validate Team Invite Permissions in github.com/mattermost/mattermost-server
osv
CVE-2025-35965UNKNOWN≥ 9.11.0+incompatible≥ 10.4.0+incompatible+1 more2025-04-24
CVE-2025-35965 Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks. NOTE: The source advisory for this report contains additional versions tha
osv