github.com/mattermost/mattermost-server/v5 known bugs
go177 known bugs in github.com/mattermost/mattermost-server/v5, with affected versions, fixes and workarounds. Sourced from upstream issue trackers.
177
bugs
Known bugs
| Severity | Affected | Fixed in | Title | Status | Source |
|---|---|---|---|---|---|
| medium | 11.3.0-rc1+incompatible | 11.3.1+incompatible | Mattermost fails to validate user's authentication method when processing account auth type switch in github.com/mattermost/mattermost-server Mattermost fails to validate user's authentication method when processing account auth type switch in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260127144908-ced9a56e3988. | fixed | osv:GO-2026-4786 |
| medium | 11.3.0-rc1+incompatible | 11.3.1+incompatible | Mattermost fails to validate team-specific upload_file permissions in github.com/mattermost/mattermost-server Mattermost fails to validate team-specific upload_file permissions in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260107144005-c7f6efdfb035. | fixed | osv:GO-2026-4749 |
| medium | 11.3.0-rc1+incompatible | 11.3.1+incompatible | Mattermost fails to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation in github.com/mattermost/mattermost-server Mattermost fails to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260129133647-5d787969c2d5. | fixed | osv:GO-2026-4746 |
| medium | 11.3.0-rc1+incompatible | 11.3.1+incompatible | Mattermost fails to properly enforce read permissions in search API endpoints in github.com/mattermost/mattermost-server Mattermost fails to properly enforce read permissions in search API endpoints in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260107142155-0481bd1fb045. | fixed | osv:GO-2026-4745 |
| medium | 11.3.0-rc1+incompatible | 11.3.1+incompatible | Mattermost fails to use consistent error responses when handling the /mute command in github.com/mattermost/mattermost-server Mattermost fails to use consistent error responses when handling the /mute command in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260130144323-5bb5261c72fa. | fixed | osv:GO-2026-4744 |
| medium | 11.3.0-rc1+incompatible | 11.3.1+incompatible | Mattermost fails to filter invite IDs based on user permissions in github.com/mattermost/mattermost-server Mattermost fails to filter invite IDs based on user permissions in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260105134819-cc427af41b2a. | fixed | osv:GO-2026-4735 |
| medium | 11.3.0-rc1+incompatible | 11.3.1+incompatible | Mattermost fails to preserve the redacted state of burn-on-read posts during deletion in github.com/mattermost/mattermost-server Mattermost fails to preserve the redacted state of burn-on-read posts during deletion in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260127062706-c6b205f0d770. | fixed | osv:GO-2026-4734 |
| medium | 11.3.0-rc1+incompatible | 11.3.1+incompatible | Mattermost fails to bound memory allocation when processing DOC files in github.com/mattermost/mattermost-server Mattermost fails to bound memory allocation when processing DOC files in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260123215601-86797c508c44. | fixed | osv:GO-2026-4733 |
| medium | 11.3.0-rc1+incompatible | 11.3.1+incompatible | Mattermost allows attackers to spoof permalink embeds in github.com/mattermost/mattermost-server Mattermost allows attackers to spoof permalink embeds in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260123211116-9efe617be8b8. | fixed | osv:GO-2026-4732 |
| medium | 11.3.0-rc1+incompatible | 11.3.1+incompatible | Mattermost fails to properly handle very long passwords in github.com/mattermost/mattermost-server Mattermost fails to properly handle very long passwords in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260129164748-7201f42d955f. | fixed | osv:GO-2026-4731 |
| medium | 11.3.0-rc1+incompatible | 11.3.1+incompatible | Mattermost allows a removed team member to enumerate all public channels within a private team in github.com/mattermost/mattermost-server Mattermost allows a removed team member to enumerate all public channels within a private team in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260113182106-a18b80ba4c32. | fixed | osv:GO-2026-4729 |
| medium | 11.3.0-rc1+incompatible | 11.3.1+incompatible | Mattermost fails to bound memory allocation when processing PSD image files in github.com/mattermost/mattermost-server Mattermost fails to bound memory allocation when processing PSD image files in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260115183946-38b413a27604. | fixed | osv:GO-2026-4727 |
| medium | 11.3.0-rc1+incompatible | 11.3.1+incompatible | Mattermost fails to limit the size of responses from integration action endpoints in github.com/mattermost/mattermost-server Mattermost fails to limit the size of responses from integration action endpoints in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260127165411-fe3052073dc6. | fixed | osv:GO-2026-4726 |
| medium | 11.3.0-rc1+incompatible | 11.3.1+incompatible | Mattermost fails to properly validate User-Agent header tokens in github.com/mattermost/mattermost-server Mattermost fails to properly validate User-Agent header tokens in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20260129181235-1346cf529aef. | fixed | osv:GO-2026-4725 |
| medium | 10.11.0+incompatible | \u2014 | Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server Mattermost fails to sanitize sensitive data in WebSocket messages in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251210191531-cd17b61de41b. | open | osv:GO-2026-4524 |
| medium | 10.11.0+incompatible | \u2014 | Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server Mattermost fails to enforce invite permissions when updating team settings in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251215190648-6404ab29acc0. | open | osv:GO-2026-4523 |
| medium | 10.11.0+incompatible | \u2014 | Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server Mattermost fails to properly validate team membership when processing channel mentions in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251209134645-761e56bb11cc. | open | osv:GO-2026-4521 |
| medium | 10.11.0+incompatible | \u2014 | Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server Mattermost fails to properly validate login method restrictions in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20251212052346-61651b0df7ea. | open | osv:GO-2026-4520 |
| medium | any | 8.0.0-20251121122154-b57c297c6d7a | Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-jira before v4.4.1. | fixed | osv:GO-2026-4275 |
| medium | 11.1.0+incompatible | 11.1.1+incompatible | Mattermost doesn't verify that post actions invoking `/share-issue-publicly` were created by the Jira plugin in github.com/mattermost/mattermost-server Mattermost doesn't verify that post actions invoking `/share-issue-publicly` were created by the Jira plugin in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20251121122154-b57c297c6d7. | fixed | osv:GO-2025-4260 |
| medium | 11.1.0+incompatible | 11.1.1+incompatible | Mattermost doesn't validate user channel membership when attaching Mattermost posts as comments to Jira issues in github.com/mattermost/mattermost-server Mattermost doesn't validate user channel membership when attaching Mattermost posts as comments to Jira issues in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20251121122154-b57c297c6d7. | fixed | osv:GO-2025-4259 |
| medium | 11.0.0-alpha.1+incompatible | 11.0.4+incompatible | Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost | fixed | osv:GO-2025-4256 |
| medium | 10.11.0-rc1+incompatible | 11.1.0+incompatible | Mattermost has missing redirect URL validation in github.com/mattermost/mattermost Mattermost has missing redirect URL validation in github.com/mattermost/mattermost.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.5-0.20251016131338-dad6bd7a1509. | fixed | osv:GO-2025-4248 |
| medium | 11.0.0-alpha.1+incompatible | 11.1.0+incompatible | Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost before v10.11.7-0.20251106103514-3b05384dd014; github.com/mattermost/mattermost-server before v10.11.7-0.20251106103514-3b05384dd014. | fixed | osv:GO-2025-4247 |
| medium | 10.11.0+incompatible | 10.11.5+incompatible | Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost | fixed | osv:GO-2025-4178 |
| medium | 10.5.0+incompatible | \u2014 | Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: . | open | osv:GO-2025-4172 |
| medium | any | 8.0.0-20251022210333-acda1fb5dd46 | Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. | fixed | osv:GO-2025-4170 |
| medium | any | 8.0.0-20251015091448-abbf01b9db45 | Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.3. | fixed | osv:GO-2025-4169 |
| medium | any | 8.0.0-20251028000919-d3ed703dc833 | Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server from v10.5.0 before v10.5.13, from v10.11.0 before v10.11.5, from v10.12.0 before v10.12.2, from v11.0.0 before v11.0.4. | fixed | osv:GO-2025-4168 |
| medium | any | 5.1.0 | Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-4146 |
| medium | 10.11.0+incompatible | 10.11.4+incompatible | Mattermost allows other users to determine when users had read channels via channel member objects in github.com/mattermost/mattermost-server Mattermost allows other users to determine when users had read channels via channel member objects in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250905150616-ba86dfc5876b6. | fixed | osv:GO-2025-4133 |
| medium | any | 11.0.0-alpha.1+incompatible | Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-4131 |
| medium | 10.12.0+incompatible | 10.12.1+incompatible | Mattermost allows system administrators to access password hashes and MFA secrets in github.com/mattermost/mattermost-server Mattermost allows system administrators to access password hashes and MFA secrets in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-4130 |
| medium | 10.12.0+incompatible | 10.12.1+incompatible | Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL in github.com/mattermost/mattermost-server Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-4129 |
| medium | any | 11.1.0+incompatible | Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-4128 |
| medium | any | 8.0.0-20250815165020-c8d66301415d | Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/v5 before v5.3.2-0.20250815165020-c8d66301415d; github.com/mattermost/mattermost-server/v5 before v5.3.2-0.20250815165020-c8d66301415d. | fixed | osv:GO-2025-4126 |
| medium | 10.11.0+incompatible | 10.11.4+incompatible | Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost | fixed | osv:GO-2025-4122 |
| medium | 10.11.0+incompatible | 10.11.3+incompatible | Mattermost has an Observable Timing Discrepancy vulnerability in github.com/mattermost/mattermost-server Mattermost has an Observable Timing Discrepancy vulnerability in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-4036 |
| medium | 10.11.0+incompatible | 10.11.2+incompatible | Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250815100400-2d5cdc6e217e. | fixed | osv:GO-2025-4035 |
| medium | 10.11.0+incompatible | 10.11.2+incompatible | Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-4032 |
| medium | 10.11.0+incompatible | 10.11.3+incompatible | Mattermost has an Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost has an Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-4030 |
| medium | 10.11.0+incompatible | 10.11.3+incompatible | Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250822083415-01b95392a450. | fixed | osv:GO-2025-4029 |
| medium | any | 0.0.0-20250716054606-3f3e3becfe1d | Mattermost boards plugin fails to restrict download access to files in github.com/mattermost/mattermost-plugin-boards Mattermost boards plugin fails to restrict download access to files in github.com/mattermost/mattermost-plugin-boards | fixed | osv:GO-2025-3978 |
| medium | 10.10.0+incompatible | 10.10.2+incompatible | Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3977 |
| medium | 10.5.0+incompatible | 10.5.10+incompatible | Mattermost Open Redirect vulnerability in github.com/mattermost/mattermost-server Mattermost Open Redirect vulnerability in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-202508080704-39bd251fe4f600. | fixed | osv:GO-2025-3960 |
| medium | 10.10.0+incompatible | 10.10.2+incompatible | Mattermost makes Use of Weak Hash in github.com/mattermost/mattermost-server Mattermost makes Use of Weak Hash in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3959 |
| medium | 10.10.0+incompatible | 10.10.2+incompatible | Mattermost Open Redirect vulnerability in github.com/mattermost/mattermost-server Mattermost Open Redirect vulnerability in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3958 |
| medium | 10.10.0+incompatible | 10.10.2+incompatible | Mattermost Missing Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Missing Authorization vulnerability in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250729073403-517ae758cd02. | fixed | osv:GO-2025-3950 |
| medium | 10.10.0+incompatible | 10.10.1+incompatible | Mattermost has Potential Server Crash due to Unvalidated Import Data in github.com/mattermost/mattermost-server Mattermost has Potential Server Crash due to Unvalidated Import Data in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250708173752-d6b35c41f0ae5. | fixed | osv:GO-2025-3911 |
| medium | 10.10.0+incompatible | 10.10.1+incompatible | Mattermost Fails to Sanitize File Names in github.com/mattermost/mattermost-server Mattermost Fails to Sanitize File Names in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250708173752-d6b35c41f0ae5. | fixed | osv:GO-2025-3910 |
| medium | 10.9.0+incompatible | 10.9.3+incompatible | Mattermost Fails to Sanitize Path Traversal Sequences in github.com/mattermost/mattermost-server Mattermost Fails to Sanitize Path Traversal Sequences in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3907 |
| medium | 10.5.0+incompatible | 10.5.10+incompatible | Mattermost Server SSRF Vulnerability via the Agents Plugin in github.com/mattermost/mattermost-server Mattermost Server SSRF Vulnerability via the Agents Plugin in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3906 |
| medium | 10.9.0+incompatible | 10.9.3+incompatible | Mattermost Does Not Sanitize the Team Invite ID in github.com/mattermost/mattermost-server Mattermost Does Not Sanitize the Team Invite ID in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3905 |
| medium | 10.10.0+incompatible | 10.10.1+incompatible | Mattermost Fails to Validate Remote Cluster Upload Sessions in github.com/mattermost/mattermost-server Mattermost Fails to Validate Remote Cluster Upload Sessions in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250708173752-d6b35c41f0ae5. | fixed | osv:GO-2025-3904 |
| medium | 10.5.0+incompatible | 10.5.9+incompatible | Mattermost Lack of Access Control Validation in github.com/mattermost/mattermost-server Mattermost Lack of Access Control Validation in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3903 |
| medium | 10.5.0+incompatible | 10.5.9+incompatible | Mattermost Fails to Properly Validate Team Role Modification in github.com/mattermost/mattermost-server Mattermost Fails to Properly Validate Team Role Modification in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3902 |
| medium | 10.9.0+incompatible | 10.9.2+incompatible | Mattermost Fails to Validate File Paths in github.com/mattermost/mattermost-server Mattermost Fails to Validate File Paths in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.0.0-20250619095651-9dd0b3943e55. | fixed | osv:GO-2025-3901 |
| medium | 10.8.0+incompatible | 10.8.2+incompatible | Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3820 |
| medium | 10.8.0+incompatible | 10.8.2+incompatible | Mattermost Missing Authentication for Critical Function in github.com/mattermost/mattermost-server Mattermost Missing Authentication for Critical Function in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3819 |
| medium | 10.5.0+incompatible | 10.5.8+incompatible | Mattermost has Insufficiently Protected Credentials in github.com/mattermost/mattermost-server Mattermost has Insufficiently Protected Credentials in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3818 |
| medium | 10.8.0+incompatible | 10.8.1+incompatible | Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3797 |
| medium | 10.8.0+incompatible | 10.8.1+incompatible | Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3796 |
| medium | 10.8.0+incompatible | 10.8.1+incompatible | Mattermost allows unauthorized channel member management through playbook runs in github.com/mattermost/mattermost-server Mattermost allows unauthorized channel member management through playbook runs in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3772 |
| medium | 10.8.0+incompatible | 10.8.1+incompatible | Mattermost allows an unauthorized Guest user access to Playbook in github.com/mattermost/mattermost-server Mattermost allows an unauthorized Guest user access to Playbook in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3771 |
| medium | 10.8.0+incompatible | 10.8.1+incompatible | Mattermost allows authenticated users to write files to arbitrary locations in github.com/mattermost/mattermost-server Mattermost allows authenticated users to write files to arbitrary locations in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3769 |
| medium | 10.5.0+incompatible | 10.5.5+incompatible | Mattermost allows guest users to view information about public teams they are not members of in github.com/mattermost/mattermost-server Mattermost allows guest users to view information about public teams they are not members of in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3757 |
| medium | 10.7.0+incompatible | 10.7.2+incompatible | Mattermost allows authenticated administrator to execute LDAP search filter injection in github.com/mattermost/mattermost-server Mattermost allows authenticated administrator to execute LDAP search filter injection in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3756 |
| medium | 10.7.0-rc1+incompatible | 10.7.1+incompatible | Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3731 |
| medium | 10.6.0-rc1+incompatible | 10.7.1+incompatible | Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3730 |
| medium | 10.7.0-rc1+incompatible | 10.7.1+incompatible | Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3729 |
| medium | 10.6.0-rc1+incompatible | 10.7.1+incompatible | Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3728 |
| medium | 10.7.0-rc1+incompatible | 10.7.1+incompatible | Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3724 |
| medium | 10.5.0+incompatible | 10.5.3+incompatible | Mattermost Fails to Check User Access to `ExperimentalSettings` in github.com/mattermost/mattermost-server Mattermost Fails to Check User Access to `ExperimentalSettings` in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3694 |
| medium | 10.6.0+incompatible | 10.6.2+incompatible | Mattermost Fails to Validate Team Invite Permissions in github.com/mattermost/mattermost-server Mattermost Fails to Validate Team Invite Permissions in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3693 |
| medium | 10.6.0+incompatible | 10.6.2+incompatible | Mattermost Fails to Lockout LDAP Users After Repeated Login Failures in github.com/mattermost/mattermost-server Mattermost Fails to Lockout LDAP Users After Repeated Login Failures in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3692 |
| medium | 10.5.0+incompatible | 10.5.3+incompatible | Mattermost Fails to Verify User's Permissions When Accessing Groups in github.com/mattermost/mattermost-server Mattermost Fails to Verify User's Permissions When Accessing Groups in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3691 |
| medium | any | 1.41.0 | Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: . | fixed | osv:GO-2025-3644 |
| medium | any | 1.41.0 | Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: . | fixed | osv:GO-2025-3643 |
| medium | any | 1.41.0 | Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: . | fixed | osv:GO-2025-3642 |
| medium | 10.5.0+incompatible | 10.5.2+incompatible | Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3623 |
| medium | 10.5.0+incompatible | 10.5.1+incompatible | Mattermost doesn't restrict domains LLM can request to contact upstream in github.com/mattermost/mattermost-server Mattermost doesn't restrict domains LLM can request to contact upstream in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3622 |
| medium | 10.5.0+incompatible | 10.5.2+incompatible | Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3621 |
| medium | 10.5.0+incompatible | 10.5.2+incompatible | Mattermost Missing Authentication for Critical Function in github.com/mattermost/mattermost-server Mattermost Missing Authentication for Critical Function in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3620 |
| medium | 10.5.0+incompatible | 10.5.2+incompatible | Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3619 |
| medium | 10.5.0+incompatible | 10.5.2+incompatible | Mattermost vulnerable to Observable Timing Discrepancy in github.com/mattermost/mattermost-plugin-msteams Mattermost vulnerable to Observable Timing Discrepancy in github.com/mattermost/mattermost-plugin-msteams.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-plugin-msteams before v2.1.0. | fixed | osv:GO-2025-3618 |
| medium | 10.5.0+incompatible | 10.5.2+incompatible | Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3611 |
| medium | 10.5.0+incompatible | 10.5.2+incompatible | Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-server Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3610 |
| medium | 10.5.0+incompatible | 10.5.2+incompatible | Mattermost Fails to Restrict Certain Operations on System Admins in github.com/mattermost/mattermost-server Mattermost Fails to Restrict Certain Operations on System Admins in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3609 |
| medium | 9.11.0+incompatible | 9.11.9+incompatible | Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` Endpoint in github.com/mattermost/mattermost-server Mattermost Fails to Enforce Proper Access Controls on `/api/v4/audits` Endpoint in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3604 |
| medium | 10.4.0+incompatible | 10.4.3+incompatible | Mattermost allows members with permission to convert public channels to private and convert private to public in github.com/mattermost/mattermost-server Mattermost allows members with permission to convert public channels to private and convert private to public in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3556 |
| medium | 9.11.0+incompatible | 9.11.9+incompatible | Mattermost fail to prompt for explicit approval before adding a team admin to a private channel in github.com/mattermost/mattermost-server Mattermost fail to prompt for explicit approval before adding a team admin to a private channel in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3555 |
| medium | 10.5.0+incompatible | 10.5.1+incompatible | Mattermost Fails to Restrict Bookmark Creation and Updates in Archived Channels in github.com/mattermost/mattermost-server Mattermost Fails to Restrict Bookmark Creation and Updates in Archived Channels in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3552 |
| medium | 10.5.0+incompatible | 10.5.1+incompatible | Mattermost Fails to Enforce MFA on Plugin Endpoints in github.com/mattermost/mattermost-server Mattermost Fails to Enforce MFA on Plugin Endpoints in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3551 |
| medium | 10.5.0+incompatible | 10.5.1+incompatible | Mattermost Fails to Restrict Command Execution in Archived Channels in github.com/mattermost/mattermost-server Mattermost Fails to Restrict Command Execution in Archived Channels in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3550 |
| medium | 10.5.0+incompatible | 10.5.1+incompatible | Mattermost Fails to Enforce Certain Search APIs in github.com/mattermost/mattermost-server Mattermost Fails to Enforce Certain Search APIs in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3549 |
| medium | 9.11.0+incompatible | 9.11.9+incompatible | Mattermost Fails to Properly Perform Viewer Role Authorization in github.com/mattermost/mattermost-server Mattermost Fails to Properly Perform Viewer Role Authorization in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3534 |
| medium | 10.4.0-rc1+incompatible | 10.4.2+incompatible | Mattermost allows reading arbitrary files in github.com/mattermost/mattermost-server Mattermost allows reading arbitrary files in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3483 |
| medium | 10.4.0-rc1+incompatible | 10.4.2+incompatible | Mattermost fails to invalidate all active sessions when converting a user to a bot in github.com/mattermost/mattermost-server Mattermost fails to invalidate all active sessions when converting a user to a bot in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3482 |
| medium | 10.4.0-rc1+incompatible | 10.4.2+incompatible | Mattermost fails to restrict channel export of archived channels in github.com/mattermost/mattermost-server Mattermost fails to restrict channel export of archived channels in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3481 |
| medium | 10.4.0-rc1+incompatible | 10.4.2+incompatible | Mattermost allows reading arbitrary files related to importing boards in github.com/mattermost/mattermost-server Mattermost allows reading arbitrary files related to importing boards in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3480 |
| medium | 10.2.0+incompatible | 10.2.1+incompatible | Mattermost webapp crash via a crafted post in github.com/mattermost/mattermost-server Mattermost webapp crash via a crafted post in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3407 |
| medium | 10.2.0+incompatible | 10.2.1+incompatible | Mattermost fails to properly validate post props in github.com/mattermost/mattermost-server Mattermost fails to properly validate post props in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3394 |
| medium | 10.2.0+incompatible | 10.2.1+incompatible | Mattermost Incorrect Type Conversion or Cast in github.com/mattermost/mattermost-server Mattermost Incorrect Type Conversion or Cast in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3393 |
| medium | 10.2.0+incompatible | 10.2.1+incompatible | Mattermost fails to properly validate post props in github.com/mattermost/mattermost-server Mattermost fails to properly validate post props in github.com/mattermost/mattermost-server | fixed | osv:GO-2025-3392 |
| medium | any | 10.3.0+incompatible | Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server Mattermost has Improper Check for Unusual or Exceptional Conditions in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: . | fixed | osv:GO-2025-3380 |
| medium | 10.2.0+incompatible | 10.2.1+incompatible | Mattermost Improper Validation of Specified Type of Input vulnerability in github.com/mattermost/mattermost-server Mattermost Improper Validation of Specified Type of Input vulnerability in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server from v9.11.0 before v9.11.16. | fixed | osv:GO-2025-3379 |
| medium | 9.11.0+incompatible | \u2014 | Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server before v9.11.16. | open | osv:GO-2025-3377 |
| medium | 10.1.0+incompatible | 10.1.3+incompatible | Mattermost Data Amplification vulnerability in github.com/mattermost/mattermost-server Mattermost Data Amplification vulnerability in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3340 |
| medium | 10.1.0+incompatible | 10.1.3+incompatible | Mattermost Race Condition vulnerability in github.com/mattermost/mattermost-server Mattermost Race Condition vulnerability in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3338 |
| medium | 10.1.0+incompatible | 10.1.3+incompatible | Mattermost Improper Validation of Specified Type of Input vulnerability in github.com/mattermost/mattermost-server Mattermost Improper Validation of Specified Type of Input vulnerability in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3337 |
| medium | any | 0.0.0-20240209181221-674f549daf0e | Mattermost Server Resource Exhaustion in github.com/mattermost/mattermost-server Mattermost Server Resource Exhaustion in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3334 |
| medium | any | 8.0.0-20240926115259-20ed58906adc | Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server Mattermost server allows authenticated user to delete arbitrary post in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3235 |
| medium | any | 8.0.0-20240926115259-20ed58906adc | Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server Mattermost Server vulnerable to application crash from attacker-generated large response in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3234 |
| medium | any | 8.0.0-20240926115259-20ed58906adc | Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3233 |
| medium | any | 8.0.0-20240813135334-8f3a13122f55 | Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server Mattermost Server allows user to get private channel names in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3232 |
| medium | any | 8.0.0-20240821220019-0d6b1070a26f | Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server Mattermost incorrectly issues two sessions when using desktop SSO in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3227 |
| medium | any | 8.0.0-20240806094731-69a8b3df0f9f | Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3164 |
| medium | 9.10.0+incompatible | 9.10.1+incompatible | Mattermost Cross-Site Request Forgery vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-Site Request Forgery vulnerability in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3097 |
| medium | 9.10.0+incompatible | 9.10.1+incompatible | Mattermost allows remote/synthetic users to create sessions, reset passwords in github.com/mattermost/mattermost-server Mattermost allows remote/synthetic users to create sessions, reset passwords in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3096 |
| medium | 9.10.0+incompatible | 9.10.1+incompatible | Mattermost doesn't restrict which roles can promote a user as system admin in github.com/mattermost/mattermost-server Mattermost doesn't restrict which roles can promote a user as system admin in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3094 |
| medium | 9.10.0+incompatible | 9.10.1+incompatible | Mattermost doesn't redact remote users' original email addresses in github.com/mattermost/mattermost-server Mattermost doesn't redact remote users' original email addresses in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3093 |
| medium | 9.9.0+incompatible | 9.9.1+incompatible | Mattermost allows unsolicited invites to expose access to local channels in github.com/mattermost/mattermost-server Mattermost allows unsolicited invites to expose access to local channels in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3092 |
| medium | 9.10.0+incompatible | 9.10.1+incompatible | Mattermost allows user with systems manager role with read-only access to teams to perform write operations on teams in github.com/mattermost/mattermost-server Mattermost allows user with systems manager role with read-only access to teams to perform write operations on teams in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3091 |
| medium | 9.10.0+incompatible | 9.10.1+incompatible | Mattermost allows team admin user without "Add Team Members" permission to disable invite URL in github.com/mattermost/mattermost-server Mattermost allows team admin user without "Add Team Members" permission to disable invite URL in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3090 |
| medium | 9.10.0+incompatible | 9.10.1+incompatible | Mattermost allows guest user with read access to upload files to a channel in github.com/mattermost/mattermost-server Mattermost allows guest user with read access to upload files to a channel in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3089 |
| medium | 9.9.0+incompatible | 9.9.1+incompatible | Mattermost did not properly restrict channel creation in github.com/mattermost/mattermost-server Mattermost did not properly restrict channel creation in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3032 |
| medium | 9.9.0+incompatible | 9.9.1+incompatible | Mattermost allows a remote actor to make an arbitrary local channel read-only in github.com/mattermost/mattermost-server Mattermost allows a remote actor to make an arbitrary local channel read-only in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3031 |
| medium | 9.9.0+incompatible | 9.9.1+incompatible | Mattermost failed to properly validate synced reactions in github.com/mattermost/mattermost-server Mattermost failed to properly validate synced reactions in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3030 |
| medium | 9.9.0+incompatible | 9.9.1+incompatible | Mattermost failed to properly validate that the channel that comes from the sync message is a shared channel in github.com/mattermost/mattermost-server Mattermost failed to properly validate that the channel that comes from the sync message is a shared channel in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3028 |
| medium | 9.9.0+incompatible | 9.9.1+incompatible | Mattermost failed to disallow the modification of local users when syncing users in shared channels in github.com/mattermost/mattermost-server Mattermost failed to disallow the modification of local users when syncing users in shared channels in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3025 |
| medium | 9.9.0+incompatible | 9.9.1+incompatible | Mattermost allows a user on a remote to set their remote username prop to an arbitrary string in github.com/mattermost/mattermost-server Mattermost allows a user on a remote to set their remote username prop to an arbitrary string in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3024 |
| medium | 9.9.0+incompatible | 9.9.1+incompatible | Mattermost allows remote actor to create/update/delete posts in arbitrary channels in github.com/mattermost/mattermost-server Mattermost allows remote actor to create/update/delete posts in arbitrary channels in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3023 |
| medium | 9.9.0+incompatible | 9.9.1+incompatible | Mattermost allows remote actor to set arbitrary RemoteId values for synced users in github.com/mattermost/mattermost-server Mattermost allows remote actor to set arbitrary RemoteId values for synced users in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3022 |
| medium | 9.9.0+incompatible | 9.9.1+incompatible | Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling in github.com/mattermost/mattermost-server Mattermost allows a remote actor to permanently delete local data by abusing dangerous error handling in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-3020 |
| medium | any | \u2014 | Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.11. | open | osv:GO-2024-2707 |
| medium | 9.5.0+incompatible | 9.5.2+incompatible | Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server Mattermost Server Improper Access Control in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 from v8.1.0 before v8.1.11. | fixed | osv:GO-2024-2706 |
| medium | 9.5.0+incompatible | 9.5.2+incompatible | Mattermost fails to authenticate the source of certain types of post actions in github.com/mattermost/mattermost-server Mattermost fails to authenticate the source of certain types of post actions in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 from v8.1.0 before v8.1.11. | fixed | osv:GO-2024-2696 |
| medium | 9.5.0+incompatible | 9.5.2+incompatible | Mattermost Server doesn't limit the number of user preferences in github.com/mattermost/mattermost-server Mattermost Server doesn't limit the number of user preferences in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 from v8.1.0 before v8.1.11. | fixed | osv:GO-2024-2695 |
| medium | 9.0.0+incompatible | 9.4.0+incompatible | Mattermost incorrectly allows access individual posts in github.com/mattermost/mattermost-server Mattermost incorrectly allows access individual posts in github.com/mattermost/mattermost-server | fixed | osv:GO-2024-2635 |
| medium | 9.0.0+incompatible | 9.4.2+incompatible | Mattermost fails to properly restrict the access of files attached to posts in github.com/mattermost/mattermost-server Mattermost fails to properly restrict the access of files attached to posts in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.9. | fixed | osv:GO-2024-2595 |
| medium | 9.4.0+incompatible | 9.4.2+incompatible | Mattermost fails to limit the number of role names in github.com/mattermost/mattermost-server Mattermost fails to limit the number of role names in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.9. | fixed | osv:GO-2024-2594 |
| medium | 9.4.0+incompatible | 9.4.2+incompatible | Mattermost fails to check the "invite_guest" permission in github.com/mattermost/mattermost-server Mattermost fails to check the "invite_guest" permission in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.9. | fixed | osv:GO-2024-2593 |
| medium | 9.3.0+incompatible | 9.3.1+incompatible | Mattermost allows attackers access to posts in channels they are not a member of in github.com/mattermost/mattermost-server Mattermost allows attackers access to posts in channels they are not a member of in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.9. | fixed | osv:GO-2024-2592 |
| medium | 9.3.0+incompatible | 9.3.1+incompatible | Mattermost post fetching without auditing in compliance export in github.com/mattermost/mattermost-server Mattermost post fetching without auditing in compliance export in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.9. | fixed | osv:GO-2024-2591 |
| medium | 9.4.0+incompatible | 9.4.2+incompatible | Mattermost leaks details of AD/LDAP groups of a teams in github.com/mattermost/mattermost-server Mattermost leaks details of AD/LDAP groups of a teams in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.9. | fixed | osv:GO-2024-2590 |
| medium | 9.3.0+incompatible | 9.3.1+incompatible | Mattermost denial of service through long emoji value in github.com/mattermost/mattermost-server Mattermost denial of service through long emoji value in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.9. | fixed | osv:GO-2024-2589 |
| medium | 9.0.0+incompatible | 9.4.2+incompatible | Mattermost race condition in github.com/mattermost/mattermost-server Mattermost race condition in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.9. | fixed | osv:GO-2024-2588 |
| medium | 9.0.0+incompatible | 9.3.0+incompatible | Mattermost fails to check the required permissions in github.com/mattermost/mattermost-server Mattermost fails to check the required permissions in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.8. | fixed | osv:GO-2024-2566 |
| medium | 9.2.0+incompatible | 9.2.4+incompatible | Mattermost vulnerable to denial of service via large number of emoji reactions in github.com/mattermost/mattermost-server Mattermost vulnerable to denial of service via large number of emoji reactions in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.8. | fixed | osv:GO-2024-2541 |
| medium | any | \u2014 | Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server Mattermost viewing archived public channels permissions vulnerability in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost-server before v7.8.10; github.com/mattermost/mattermost/server/v8 before v8.1.1. | open | osv:GO-2024-2450 |
| medium | any | 8.1.7+incompatible | Mattermost notified all users in the channel when using WebSockets to respond individually in github.com/mattermost/mattermost-server Mattermost notified all users in the channel when using WebSockets to respond individually in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. | fixed | osv:GO-2024-2448 |
| medium | any | \u2014 | Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server Mattermost Cross-site Scripting vulnerability in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. | open | osv:GO-2024-2446 |
| medium | any | \u2014 | Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server Mattermost allows demoted guests to change group names in github.com/mattermost/mattermost-server.
NOTE: The source advisory for this report contains additional versions that could not be automatically mapped to standard Go module versions.
(If this is causing false-positive reports from vulnerability scanners, please suggest an edit to the report.)
The additional affected modules and versions are: github.com/mattermost/mattermost/server/v8 before v8.1.7. | open | osv:GO-2024-2444 |
| medium | any | 5.20.0 | Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost Mattermost Server Sensitive Data Exposure in github.com/mattermost/mattermost | fixed | osv:GO-2023-1939 |
| medium | any | 5.37.9 | Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server Improper Privilege Management in Mattermost in github.com/mattermost/mattermost-server | fixed | osv:GO-2022-0616 |
| medium | any | 5.39.0 | Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server Cross-site Scripting in Mattermost in github.com/mattermost/mattermost-server | fixed | osv:GO-2022-0604 |
| medium | any | 6.5.0 | Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server Improper Control of a Resource Through its Lifetime in Mattermost in github.com/mattermost/mattermost-server | fixed | osv:GO-2022-0599 |
| medium | any | 6.4.2 | Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server Resource exhaustion in Mattermost in github.com/mattermost/mattermost-server | fixed | osv:GO-2022-0595 |
| medium | 6.4.0 | 6.5.0 | Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server Insecure plugin handling in Mattermost in github.com/mattermost/mattermost-server | fixed | osv:GO-2022-0576 |
| medium | 6.7.0 | 6.7.1 | Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server Mattermost users could access some sensitive information via API call in github.com/mattermost/mattermost-server | fixed | osv:GO-2022-0540 |
| medium | 10.8.0 | 10.8.4 | Mattermost Fails to Sanitize Path Traversal Sequences Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fails to sanitize path traversal sequences in template file destination paths, which allows a system admin to perform path traversal attacks via malicious path components, potentially enabling malicious file placement outside intended directories. | fixed | osv:GHSA-x67c-v8jr-p29r |
| medium | 5.4.0-rc1 | 7.8.12 | Mattermost password hash disclosure vulnerability Mattermost fails to properly sanitize the user object when updating the username, resulting in the password hash being included in the response body. | fixed | osv:GHSA-r67m-mf7v-qp7j |
| medium | 10.8.0 | 10.8.4 | Mattermost Does Not Sanitize the Team Invite ID Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2 fail to sanitize the team invite ID in the POST /api/v4/teams/:teamId/restore endpoint which allows an team admin with no member invite privileges to get the team’s invite id. | fixed | osv:GHSA-qj47-w9f2-qg44 |
| medium | 6.4.0 | 6.4.2 | Improper Privilege Management in Mattermost One of the API in Mattermost version 6.4.1 and earlier fails to properly protect the permissions, which allows the authenticated members with restricted custom admin role to bypass the restrictions and view the server logs and server config.json file contents. Per the Mattermost security updates page, versions 6.4.2, 6.3.5, 6.2.5, and 5.37.9 contain patches for this issue | fixed | osv:GHSA-qggc-pj29-j27m |
| medium | 10.8.0 | 10.8.4 | Mattermost Fails to Validate Remote Cluster Upload Sessions Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.9.x <= 10.9.2, 10.10.x <= 10.10.0 fail to validate upload types in remote cluster upload sessions which allows a system admin to upload non-attachment file types via shared channels that could potentially be placed in arbitrary filesystem directories. | fixed | osv:GHSA-q453-638c-h4mr |
| medium | any | 8.0.0-20250815165020-c8d66301415d | Mattermost fails to properly restrict access to archived channel search API Mattermost versions < 11 fail to properly restrict access to archived channel search API which allows guest users to discover archived public channels via the `/api/v4/teams/{team_id}/channels/search_archived` endpoint | fixed | osv:GHSA-j6gg-r5jc-47cm |
| medium | any | 5.20.0 | Mattermost Server Sensitive Data Exposure An issue was discovered in Mattermost Server before 5.20.0. Non-members can receive broadcasted team details via the `update_team` WebSocket event, aka MMSA-2020-0012. | fixed | osv:GHSA-j2h2-cvwh-cr64 |
| medium | any | 5.39.0 | Cross-site Scripting in Mattermost Mattermost 5.38 and earlier fails to sufficiently sanitize clipboard contents, which allows a user-assisted attacker to inject arbitrary web script in product deployments that explicitly disable the default CSP. | fixed | osv:GHSA-hv5f-73mr-7vvj |
| medium | 10.8.0 | 10.8.4 | Mattermost has Potential Server Crash due to Unvalidated Import Data Mattermost versions 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17, 10.10.x <= 10.10.0, 10.9.x <= 10.9.3 fail to validate import data which allows a system admin to crash the server via the bulk import feature. | fixed | osv:GHSA-h469-4fcf-p23h |
| medium | 10.9.0 | 10.9.2 | Mattermost Fails to Validate File Paths Mattermost versions 10.9.x <= 10.9.1, 10.8.x <= 10.8.3, 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate file paths during plugin import operations which allows restricted admin users to install unauthorized custom plugins via path traversal in the import functionality, bypassing plugin signature enforcement and marketplace restrictions. | fixed | osv:GHSA-gq3r-5833-5532 |
| medium | 3.3.0 | 7.1.6 | Mattermost fails to properly authentication inviter's permissions to private channel When processing an email invite to a private channel on a team, Mattermost fails to validate the inviter's permission to that channel, allowing an attacker to invite themselves to a private channel.
[Issue Identifier](https://mattermost.com/security-updates/): MMSA-2023-00137 | fixed | osv:GHSA-9hj7-v56g-rhf6 |
| medium | 3.3.0 | 7.1.6 | Mattermost vulnerable to information disclosure When running in a High Availability configuration, Mattermost fails to sanitize some of the `user_updated` and` post_deleted` events broadcast to all users, leading to disclosure of sensitive information to some of the users with currently connected Websocket clients.
[Issue Identifier](https://mattermost.com/security-updates/): MMSA-2023-00138 | fixed | osv:GHSA-8jhh-3jf2-pfwr |
| medium | 6.0.0 | 7.1.6 | Mattermost vulnerable to cross-site scripting (XSS) Boards in Mattermost allows an attacker to upload a malicious SVG image file as an attachment to a card and share it using a direct link to the file.
[Issue Identifier](https://mattermost.com/security-updates/): MMSA-2023-00139 | fixed | osv:GHSA-63f2-6959-2pxj |
| low | 9.5.0 | 9.5.7 | Mattermost did not properly restrict channel creation Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary channels, when shared channels were enabled. | fixed | osv:GHSA-vvpg-55p7-5h8w |
| low | any | 0.0.0-20240209181221-674f549daf0e | Mattermost Server Resource Exhaustion Resource Exhaustion in Mattermost Server versions 8.1.x before 8.1.10 fails to limit the size of the payload that can be read and parsed allowing an attacker to send a very large email payload and crash the server.
| fixed | osv:GHSA-qqc8-rv37-79q5 |
| low | 10.11.0 | 10.11.4 | Mattermost Incorrect Authorization vulnerability Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API, which allows users from one team to access user metadata and channel membership information from other teams via the API endpoint. | fixed | osv:GHSA-mqcj-8c2g-h97q |
| low | 10.5.0 | 10.5.9 | Mattermost Fails to Properly Validate Team Role Modification Mattermost versions 10.5.x <= 10.5.8, 9.11.x <= 9.11.17 fail to properly validate authorization for team scheme role modifications which allows Team Admins to demote Team Members to Guests via the PUT /api/v4/teams/team-id/members/user-id/schemeRoles API endpoint. | fixed | osv:GHSA-4276-cm8c-788h |
API access
Get this data programmatically \u2014 free, no authentication.
curl https://depscope.dev/api/bugs/go/github.com/mattermost/mattermost-server/v5