Mattermost is an open source platform for secure collaboration across the entire software development lifecycle..
github.com/mattermost/[email protected]+incompatible has vulnerabilities — update to latest
Update to >= 8.0.0-20260407102538-faa7d75b4ea0 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| medium | CVE-2025-32093 | Mattermost Fails to Restrict Certain Operations on System Admins | 8.0.0-20250227102013-aa4623a93199 |
| medium | CVE-2026-0999 | Mattermost fails to properly validate login method restrictions | 5.3.2-0.20251212052346-61651b0df7ea |
| medium | BIT-mattermost-2023-1777 | Mattermost vulnerable to information disclosure | 1.4.1-0.20230301145909-10be118d99a5 |
| low | CVE-2025-53971 | Mattermost Fails to Properly Validate Team Role Modification | 8.0.0-20250721095846-c602a4a78e1f |
| medium | CVE-2026-3113 | Mattermost doesn't set permissions on downloaded bulk export | 8.0.0-20260217110922-b7d4a1f1f59b |
| low | CVE-2025-6227 | Mattermost has Insufficiently Protected Credentials | 8.0.0-20250612074655-8f8612c63783 |
| medium | CVE-2025-14350 | Mattermost fails to properly validate team membership when processing channel mentions | 5.3.2-0.20251209134645-761e56bb11cc |
| medium | CVE-2026-4915 | Mattermost doesn't filter nil elements from outgoing webhook attachment payloads before processing | 8.0.0-20260407102538-faa7d75b4ea0 |
| high | CVE-2025-9072 | Mattermost Open Redirect vulnerability | 8.0.0-20250731063404-9eebaadf8f72 |
| medium | CVE-2025-6226 | Mattermost Missing Authentication for Critical Function | 8.0.0-20250520130510-fa40a8c5d47f |
| medium | CVE-2026-28759 | Mattermost does not verify remote cluster channel access when processing shared channel membership removals | 5.3.2-0.20260216150504-8738f8c4b3d4 |
| medium | CVE-2026-5163 | Mattermost doesn't verify channel membership when processing AI-assisted message rewrites | 5.3.2-0.20260401090745-f4d1abe7e8f5 |
| low | CVE-2025-55074 | Mattermost allows other users to determine when users had read channels via channel member objects | 8.0.0-20250905150616-ba86dfc5876b6 |
| high | CVE-2026-6346 | Mattermost doesn't sanitize sensitive configuration fields before including them in support packet generation | 5.3.2-0.20260326202606-fac92f4a71f3 |
| medium | CVE-2025-9078 | Mattermost makes Use of Weak Hash | 8.0.0-20250718075842-cd87e5c87737 |
| low | CVE-2025-14573 | Mattermost fails to enforce invite permissions when updating team settings | 5.3.2-0.20251215190648-6404ab29acc0 |
| medium | CVE-2026-6340 | Mattermost doesn't validate 7zip archive structure before processing | 5.3.2-0.20260325191733-fb11968f8798 |
| medium | CVE-2025-55073 | Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL | 8.0.0-20250929212932-a41db04d2746 |
| medium | CVE-2026-27656 | Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw | 8.0.0-20260217110922-b7d4a1f1f59b |
| medium | CVE-2025-36530 | Mattermost Fails to Validate File Paths | 8.0.0-20250619095651-9dd0b3943e55 |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/go/github.com/mattermost/mattermost-serverLast updated · 2026-07-07T06:50:46Z