github.com/mattermost/mattermost-server
Go284 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/mattermost/mattermost-serverpage 6 of 6
- CVE-2026-3108HIGHCVSS 8.8EG 8.8✓ Fixed in 11.4.1+incompatible2026-03-26
Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to sanitize user-controlled post content in the mmctl commands terminal output which allows attackers to manipulate administrator terminals …
- CVE-2026-3112MEDIUMCVSS 4.9EG 4.9✓ Fixed in 11.4.1+incompatible2026-03-26
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate Advanced Logging file target paths which allows system administrators to read arbitrary host files via malicious AdvancedLogging…
- CVE-2026-3113MEDIUMCVSS 5.5EG 5.5✓ Fixed in 11.4.1+incompatible2026-03-26
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to set permissions on downloaded bulk export which allows other local users on the server to be able to read contents of the bulk export.. M…
- CVE-2026-3114MEDIUMCVSS 6.5EG 6.5✓ Fixed in 11.4.1+incompatible2026-03-26
Mattermost versions 11.4.x <= 11.4.0, 11.3.x <= 11.3.1, 11.2.x <= 11.2.3, 10.11.x <= 10.11.11 fail to validate decompressed archive entry sizes during file extraction which allows authenticated users with file upload permissions to cause a…
- CVE-2026-3115MEDIUMCVSS 4.3EG 4.3✓ Fixed in 11.4.1+incompatible2026-03-26
Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to apply view restrictions when retrieving group member IDs, which allows authenticated guest users to enumerate user IDs outside their allo…
- CVE-2026-3473HIGHCVSS 7.1EG 7.1✓ Fixed in 11.6.1+incompatible2026-05-26
vulnerable: 11.6.0
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate file ownership and access control, which allows an authenticated user to access and download files belonging to other users or t…
- CVE-2026-3495LOWCVSS 3.8EG 3.8✓ Fixed in 11.5.2+incompatible2026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to escape some variables that could contain malicious content during error page composition which allows an attacker with access to edit some site configuration to execute some…
- CVE-2026-3590MEDIUMCVSS 6.5EG 6.5✓ Fixed in 11.5.0+incompatible2026-04-15
vulnerable: 11.5.0-rc1
Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic single-use consumption of guest magic link tokens, which allows an attacker with access to a valid magic link to establish…
- CVE-2026-3636MEDIUMCVSS 4.3EG 4.3✓ Fixed in 11.6.1+incompatible2026-05-26
vulnerable: 11.6.0
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to sanitize team member data when returned via API to users without elevated permissions which allows a user without permissions to get data…
- CVE-2026-3637MEDIUMCVSS 4.3EG 4.3✓ Fixed in 11.5.2+incompatible2026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check the create_post channel permission during post edit operations which allows an authenticated attacker with revoked posting privileges to modify their…
- CVE-2026-4053LOWCVSS 3.1EG 3.1✓ Fixed in 11.5.2+incompatible2026-05-15
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce the PostEditTimeLimit on non-message post fields which allows an authenticated user to modify post file attachments, props, and pin status after the edit window has …
- CVE-2026-4054MEDIUMCVSS 4.3EG 4.3✓ Fixed in 11.5.2+incompatible2026-05-15
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to validate the response body of proxied images, which allows a remote attacker to enact client-side DoS via an SVG file served from an attacker-controlled or…
- CVE-2026-4055MEDIUMCVSS 4.3EG 4.32026-05-21
Mattermost versions 11.5.x <= 11.5.1 fail to validate team-level run_create permission against the target team when creating a playbook run which allows an authenticated team member to create runs in teams where they lack permission via sp…
- CVE-2026-4265MEDIUMCVSS 4.3EG 4.3✓ Fixed in 11.3.1+incompatible2026-03-16
Mattermost versions 11.3.x <= 11.3.0, 11.2.x <= 11.2.2, 10.11.x <= 10.11.10 fail to validate team-specific upload_file permissions which allows a guest user to post files in channels where they lack upload_file permission via uploading fil…
- CVE-2026-4273LOWCVSS 3.7EG 3.7✓ Fixed in 11.5.2+incompatible2026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation which allows an authenticated attacker to bypass token rota…
- CVE-2026-4274MEDIUMCVSS 5.4EG 5.4✓ Fixed in 11.4.1+incompatible2026-03-26
Mattermost versions 11.2.x <= 11.2.2, 10.11.x <= 10.11.10, 11.4.x <= 11.4.0, 11.3.x <= 11.3.1 fail to restrict team-level access when processing membership sync from a remote cluster, which allows a malicious remote cluster to grant a user…
- CVE-2026-4286LOWCVSS 3.1EG 3.1✓ Fixed in 11.5.2+incompatible2026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to check if {{team_id}} was being changed when updating playbooks, allowing users with only {{Manage Playbook Configurations}} permission to change a playbook's team, bypassing…
- CVE-2026-4635MEDIUMCVSS 5.3EG 5.3✓ Fixed in 11.6.1+incompatible2026-05-26
vulnerable: 11.6.0
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to archive the channel before removing persistent notifications which allows authenticated user to crash the server via timing the creation …
- CVE-2026-4646MEDIUMCVSS 4.3EG 4.3✓ Fixed in 11.6.1+incompatible2026-05-26
vulnerable: 11.6.0
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate user-supplied input in API request handlers which allows an authenticated attacker to crash the plugin process via a crafted HTT…
- CVE-2026-4858CRITICALCVSS 9.9EG 9.9✓ Fixed in 11.6.1+incompatible2026-05-21
vulnerable: 11.6.0
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which allows an malicious authenticated user to call an arbitrary API via system admin Mattermo…
- CVE-2026-4915MEDIUMCVSS 6.5EG 6.5✓ Fixed in 11.6.1+incompatible2026-05-25
vulnerable: 11.6.0
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to filter nil elements from outgoing webhook attachment payloads before processing, which allows an authenticated user to cause a denial of …
- CVE-2026-5163MEDIUMCVSS 6.5EG 6.5✓ Fixed in 11.5.2+incompatible2026-05-18
Mattermost versions 11.5.x <= 11.5.1 fail to verify channel membership when processing AI-assisted message rewrites which allows an authenticated attacker to read the content of threads in private channels and direct messages they do not h…
- CVE-2026-5308HIGHCVSS 7.5EG 7.5✓ Fixed in 11.6.1+incompatible2026-05-26
vulnerable: 11.6.0
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to enforce request body size limits on plugin HTTP endpoints which allows an attacker to cause a denial of service via crafted oversized HTT…
- CVE-2026-5740HIGHCVSS 7.5EG 7.5✓ Fixed in 11.6.1+incompatible2026-05-26
vulnerable: 11.6.0
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to properly validate msgpack-encoded WebSocket frames before memory allocation which allows an unauthenticated remote attacker to crash the …
- CVE-2026-5755MEDIUMCVSS 6.5EG 6.5✓ Fixed in 11.6.1+incompatible2026-05-26
vulnerable: 11.6.0
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.2, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the TIFF IFD offset in the image header before allocating memory, which allows authenticated users with file u…
- CVE-2026-6333LOWCVSS 3.5EG 3.5✓ Fixed in 11.5.2+incompatible2026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response URLs for custom slash commands which allows an authenticated attacker to redirect slash command responses to an attacker-…
- CVE-2026-6334LOWCVSS 3.1EG 3.1✓ Fixed in 11.5.2+incompatible2026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to enforce client identity binding during the OAuth authorization code redemption flow which allows an authenticated OAuth client to redeem authorization codes issued to a diff…
- CVE-2026-6339MEDIUMCVSS 4.3EG 4.3✓ Fixed in 11.5.2+incompatible2026-05-18
Mattermost versions 11.5.x <= 11.5.1, 11.4.x <= 11.4.3 fail to validate the X-Requested-With header on the burn-on-read reveal endpoint which allows an authenticated channel member to force the reveal of a burn-on-read message without reci…
- CVE-2026-6340MEDIUMCVSS 4.3EG 4.3✓ Fixed in 11.5.2+incompatible2026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to validate 7zip archive structure before processing which allows an authenticated attacker to cause server memory exhaustion and denial of service via upload…
- CVE-2026-6343MEDIUMCVSS 4.3EG 4.3✓ Fixed in 11.5.2+incompatible2026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check public/private permissions which allows members without these permissions to access public playbooks via /get.. Mattermost Advisory ID: MMSA-2026-005…
- CVE-2026-6345MEDIUMCVSS 6.5EG 6.5✓ Fixed in 11.5.2+incompatible2026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail prevent disclosure of created user password which allows a malicious attacker to impersonate a user via the use of some of those passwords.. Mattermost Adviso…
- CVE-2026-6346HIGHCVSS 8.7EG 8.7✓ Fixed in 11.5.2+incompatible2026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields before including them in support packet generation, which allows a Mattermost System Admin or any party with access…
- CVE-2026-6347HIGHCVSS 7.6EG 7.6✓ Fixed in 11.5.2+incompatible2026-05-18
Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields in the Mattermost Calls plugin which allows an attacker with access to a support packet to obtain TURN server crede…
- CVE-2026-7387HIGHCVSS 8.8EG 8.8✓ Fixed in 11.6.12026-06-12
vulnerable: 11.6.0
Mattermost versions 11.6.x <= 11.6.1, 11.5.x <= 11.5.4, 10.11.x <= 10.11.15, 10.11.x <= 10.11.16 Mattermost fails to require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints, which…
Check whether github.com/mattermost/mattermost-server is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/mattermost/mattermost-server CVEs against the assets you own.
Start Free Scan →