github.com/mattermost/mattermost-plugin-calls
Go3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/mattermost/mattermost-plugin-callspage 1 of 1
- CVE-2025-12689MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.11.02025-12-17
Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 fail to check WebSocket request field for proper UTF-8 format, which allows attacker to crash Calls plug-in via sending malformed request.
- CVE-2025-62190MEDIUMCVSS 4.3EG 4.3✓ Fixed in 1.10.02025-12-17
Mattermost versions 11.0.x <= 11.0.4, 10.12.x <= 10.12.2, 10.11.x <= 10.11.6 and Mattermost Calls versions <=1.10.0 fail to implement CSRF protection on the Calls widget page which allows an authenticated attacker to initiate calls and inj…
- CVE-2026-6347HIGHCVSS 7.6EG 7.6✓ Fixed in 1.12.0-rc22026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields in the Mattermost Calls plugin which allows an attacker with access to a support packet to obtain TURN server crede…
Check whether github.com/mattermost/mattermost-plugin-calls is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/mattermost/mattermost-plugin-calls CVEs against the assets you own.
Start Free Scan →