Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack the GitHub reaction feature to make users add reactions to arbitrary GitHub objects via crafted notification posts.
References
| Link | Resource |
|---|---|
| https://mattermost.com/security-updates | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2025-12-17 13:15
Updated : 2025-12-29 18:50
NVD link : CVE-2025-13352
Mitre link : CVE-2025-13352
CVE.ORG link : CVE-2025-13352
JSON object : View
Products Affected
mattermost
- mattermost_server
CWE
CWE-1287
Improper Validation of Specified Type of Input
