{"package":"github.com/mattermost/mattermost-plugin-playbooks","ecosystem":"go","latest_version":"v1.41.1","description":"Mattermost Playbooks enable reliable and repeatable processes for your teams using checklists, automation, and retrospectives.","license":"Apache-2.0","license_risk":"permissive","commercial_use_notes":"Permissive: commercial closed-source use OK; preserve the copyright notice.","homepage":"https://pkg.go.dev/github.com/mattermost/mattermost-plugin-playbooks","repository":"https://github.com/mattermost/mattermost-plugin-playbooks","downloads_weekly":93,"health":{"score":48,"risk":"high","breakdown":{"maintenance":5,"popularity":0,"security":23,"maturity":15,"community":5},"deprecated":false,"max_score":100},"vulnerabilities":{"count":6,"critical":0,"high":0,"medium":1,"low":5,"details":[{"vuln_id":"CVE-2026-26304","severity":"medium","summary":"Mattermost fails to verify run_create permission for empty playbookId","affected_versions":"<1.41.1-0.20260316224925-705f54a81841","fixed_version":"1.41.1-0.20260316224925-705f54a81841","source":"osv","published_at":"2026-03-16T21:34:32Z","in_kev":false,"epss_prob":0.00036,"epss_percentile":0.10513,"threat_tier":"theoretical"},{"vuln_id":"CVE-2025-41423","severity":"low","summary":"Mattermost Playbooks fails to properly validate permissions","affected_versions":">=2.0.0|<1.41.0|<8.0.0-20250218121836-2b5275d87136|>=10.4.0|>=10.5.0|>=9.11.0","fixed_version":"8.0.0-20250218121836-2b5275d87136","source":"osv","published_at":"2025-04-24T09:30:33Z","in_kev":false,"epss_prob":0.00042,"epss_percentile":0.12518,"threat_tier":"theoretical"},{"vuln_id":"CVE-2025-41395","severity":"unknown","summary":"Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks","affected_versions":"<1.41.0|>=9.11.0+incompatible|>=10.4.0+incompatible|>=10.5.0+incompatible|<8.0.0-20250218121836-2b5275d87136","fixed_version":"8.0.0-20250218121836-2b5275d87136","source":"osv","published_at":"2025-04-24T18:14:57Z","in_kev":false,"epss_prob":0.00132,"epss_percentile":0.32395,"threat_tier":"theoretical"},{"vuln_id":"CVE-2025-35965","severity":"unknown","summary":"Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks","affected_versions":"<1.41.0|>=9.11.0+incompatible|>=10.4.0+incompatible|>=10.5.0+incompatible|<8.0.0-20250218121836-2b5275d87136","fixed_version":"8.0.0-20250218121836-2b5275d87136","source":"osv","published_at":"2025-04-24T18:14:57Z","in_kev":false,"epss_prob":0.00337,"epss_percentile":0.56491,"threat_tier":"theoretical"},{"vuln_id":"CVE-2025-41423","severity":"unknown","summary":"Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks","affected_versions":"<1.41.0|>=9.11.0+incompatible|>=10.4.0+incompatible|>=10.5.0+incompatible|<8.0.0-20250218121836-2b5275d87136","fixed_version":"8.0.0-20250218121836-2b5275d87136","source":"osv","published_at":"2025-04-24T18:14:57Z","in_kev":false,"epss_prob":0.00042,"epss_percentile":0.12518,"threat_tier":"theoretical"},{"vuln_id":"CVE-2026-26304","severity":"unknown","summary":"Mattermost fails to verify run_create permission for empty playbookId in github.com/mattermost/mattermost-plugin-playbooks","affected_versions":"<1.41.1-0.20260316224925-705f54a81841","fixed_version":"1.41.1-0.20260316224925-705f54a81841","source":"osv","published_at":"2026-03-23T18:16:18Z","in_kev":false,"epss_prob":0.00036,"epss_percentile":0.10513,"threat_tier":"theoretical"}],"actively_exploited_count":0,"likely_exploited_count":0},"versions":{"latest":"v1.41.1","total_count":170,"recent":["v1.25.0-rc3","v1.9.2","v0.5.0-alpha.2","v1.29.0","v1.13.0","v1.23.0","v1.32.3","v1.14.2","v1.16.0","v1.15.0","v1.26.0","v0.7.0-alpha.2","v1.27.0-rc2","v1.21.0-alpha.2","v1.1.0","v0.5.0-alpha.4","v0.2.0","v1.34.0-alpha.2","v1.13.0-alpha.3","v1.34.0-alpha.1"]},"metadata":{"deprecated":false,"deprecated_message":null,"maintainers_count":164,"first_published":null,"last_published":"2025-03-19T11:51:30Z","dependencies_count":0,"dependencies":[]},"github_stats":null,"bundle":null,"typescript":null,"known_issues":{"bugs_count":0,"bugs_severity":{},"status_breakdown":{},"link":null,"scope":"none"},"historical_compromise":null,"recommendation":{"action":"use_with_caution","issues":["Moderate health score (48/100) — verify manually"],"use_version":"v1.41.1","version_hint":"Update to >= 1.41.1-0.20260316224925-705f54a81841 to fix known vulnerabilities","summary":"github.com/mattermost/mattermost-plugin-playbooks@v1.41.1 low health (48/100) — consider alternatives"},"version_scoped":null,"requested_version":null,"_cache":"miss","_response_ms":2018,"_powered_by":"depscope.dev — free package intelligence for AI agents","typosquat":{"is_suspected":false},"maintainer_trust":{"available":false},"malicious":{"is_malicious":false},"scorecard":{"available":false},"quality":{"available":false},"version_history_summary":{"total_versions":21,"first_release_age_days":null,"last_release_days_ago":409,"avg_days_between_releases":null,"release_velocity":"stale"}}