depscope
Packages
IntegrateAPI DocsCuratorBenchmarkCoverage
Sign inGet API access

Related on DepScope

Known bugs
384 non-CVE bugs →
More
  • All Go packages →
  • Breaking changes index →
  • Bug index →
  • AI hallucination corpus →
depscope/go/github.com/mattermost/mattermost-server

github.com/mattermost/mattermost-server

govv11.9.0+incompatible

Mattermost is an open source platform for secure collaboration across the entire software development lifecycle..

License Apache-2.0permissive972 versions1212 maintainers0 deps38,831 weekly dl
mattermost/mattermost-server
60
/ 100
Health
update required

github.com/mattermost/[email protected]+incompatible has vulnerabilities — update to latest

Update to >= 8.0.0-20260407102538-faa7d75b4ea0 to fix known vulnerabilities

  • Moderate health score (60/100) — verify manually
  • 7 high severity vulnerabilities
Health breakdown0 – 100
25/25
maintenance
10/20
popularity
0/25
security
15/15
maturity
13/15
community
Vulnerabilities
178
7 high33 medium138 low
Advisories (178)
SeverityIDSummaryFixed in
mediumCVE-2025-32093Mattermost Fails to Restrict Certain Operations on System Admins8.0.0-20250227102013-aa4623a93199
mediumCVE-2026-0999Mattermost fails to properly validate login method restrictions5.3.2-0.20251212052346-61651b0df7ea
mediumBIT-mattermost-2023-1777Mattermost vulnerable to information disclosure1.4.1-0.20230301145909-10be118d99a5
lowCVE-2025-53971Mattermost Fails to Properly Validate Team Role Modification8.0.0-20250721095846-c602a4a78e1f
mediumCVE-2026-3113Mattermost doesn't set permissions on downloaded bulk export8.0.0-20260217110922-b7d4a1f1f59b
lowCVE-2025-6227Mattermost has Insufficiently Protected Credentials8.0.0-20250612074655-8f8612c63783
mediumCVE-2025-14350Mattermost fails to properly validate team membership when processing channel mentions5.3.2-0.20251209134645-761e56bb11cc
mediumCVE-2026-4915Mattermost doesn't filter nil elements from outgoing webhook attachment payloads before processing8.0.0-20260407102538-faa7d75b4ea0
highCVE-2025-9072Mattermost Open Redirect vulnerability8.0.0-20250731063404-9eebaadf8f72
mediumCVE-2025-6226Mattermost Missing Authentication for Critical Function8.0.0-20250520130510-fa40a8c5d47f
mediumCVE-2026-28759Mattermost does not verify remote cluster channel access when processing shared channel membership removals5.3.2-0.20260216150504-8738f8c4b3d4
mediumCVE-2026-5163Mattermost doesn't verify channel membership when processing AI-assisted message rewrites5.3.2-0.20260401090745-f4d1abe7e8f5
lowCVE-2025-55074Mattermost allows other users to determine when users had read channels via channel member objects8.0.0-20250905150616-ba86dfc5876b6
highCVE-2026-6346Mattermost doesn't sanitize sensitive configuration fields before including them in support packet generation5.3.2-0.20260326202606-fac92f4a71f3
mediumCVE-2025-9078Mattermost makes Use of Weak Hash8.0.0-20250718075842-cd87e5c87737
lowCVE-2025-14573Mattermost fails to enforce invite permissions when updating team settings5.3.2-0.20251215190648-6404ab29acc0
mediumCVE-2026-6340Mattermost doesn't validate 7zip archive structure before processing5.3.2-0.20260325191733-fb11968f8798
mediumCVE-2025-55073Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL8.0.0-20250929212932-a41db04d2746
mediumCVE-2026-27656Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw8.0.0-20260217110922-b7d4a1f1f59b
mediumCVE-2025-36530Mattermost Fails to Validate File Paths8.0.0-20250619095651-9dd0b3943e55
... and 158 more
Maintainer trust
Active maintainers (3m)
1
Contributors (12m)
0
Primary author dominance
0%
GitHub stars
36,447
single active maintainer 3m

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/go/github.com/mattermost/mattermost-server

Last updated · 2026-07-07T06:50:46Z

DepScope

Package intelligence for AI agents. 19 ecosystems.

Resources
API DocumentationHallucination BenchmarkFor EnterpriseSwagger / OpenAPIPopular PackagesCoverageAI Plugin SetupWatch the pitch (60s)
Legal
Legal hubPrivacy PolicyTerms of ServiceCookie PolicyAcceptable UseAttributionDPASub-processorsSecurityImprintContact中文
© 2026 Cuttalo srl — Italy · VAT IT03242390734Built for AI agents