GHSA-r5vf-grcx-5vqpMediumCVSS 5.4

Mattermost allows authenticated users to gain access to private repositories

Published
May 26, 2026
Last Modified
June 29, 2026

🔗 CVE IDs covered (1)

📋 Description

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the OAuth token scope on the callback which allows an authenticated Mattermost user to gain access to private repositories via modifying the scope parameter in the GitHub authorization URL. Mattermost Advisory ID: MMSA-2026-00628

🎯 Affected products5

  • go/github.com/mattermost/mattermost-server:= 11.6.0
  • go/github.com/mattermost/mattermost-server:>= 11.5.0, < 11.5.4
  • go/github.com/mattermost/mattermost-server:>= 11.4.0, < 11.4.5
  • go/github.com/mattermost/mattermost-server:>= 10.11.0, < 10.11.15
  • go/github.com/mattermost/mattermost-plugin-github:< 1.0.1-0.20260318132218-6e6b740c4852

🔗 References (4)