github.com/mattermost/mattermost-plugin-github
Go4 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/mattermost/mattermost-plugin-githubpage 1 of 1
- CVE-2025-13352LOWCVSS 3.0EG 3.0✓ Fixed in 1.0.1-0.20250829075715-0deffcfc6bee2025-12-17
Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack the GitHub reaction feature to make users add reactions to ar…
- CVE-2026-28735MEDIUMCVSS 5.4EG 5.4✓ Fixed in 1.0.1-0.20260318132218-6e6b740c48522026-05-26
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the OAuth token scope on the callback which allows an authenticated Mattermost user to gain access to private repositories via m…
- CVE-2026-4646MEDIUMCVSS 4.3EG 4.3✓ Fixed in 1.0.1-0.20260330164815-c2840e980b3c2026-05-26
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate user-supplied input in API request handlers which allows an authenticated attacker to crash the plugin process via a crafted HTT…
- CVE-2026-5308HIGHCVSS 7.5EG 7.5✓ Fixed in 1.0.1-0.20260410143745-9b41b1fd43c42026-05-26
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to enforce request body size limits on plugin HTTP endpoints which allows an attacker to cause a denial of service via crafted oversized HTT…
Check whether github.com/mattermost/mattermost-plugin-github is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/mattermost/mattermost-plugin-github CVEs against the assets you own.
Start Free Scan →