Vulnerabilities in Mattermost

489 results
Vexday analysis

Com 434 CVEs catalogadas e nenhuma entrada confirmada no catálogo CISA KEV, o Mattermost apresenta taxa de exploração ativa abaixo da média geral do catálogo, o que indica risco operacional imediato relativamente contido. No entanto, o volume de 60 vulnerabilidades surgidas nos últimos 90 dias merece atenção, sinalizando um ritmo elevado de descoberta recente. A falha mais comum é CWE-863 (autorização incorreta), padrão que tende a permitir acesso não autorizado a recursos e funcionalidades, e que exige revisão cuidadosa de controles de acesso nas implementações. A CVE mais perigosa atualmente identificada, CVE-2025-25279, registra escore EPSS de 0,2081 — o mais alto observado no portfólio — e, embora ainda sem exploração confirmada, deve ser priorizada dado o risco potencial de aproveitamento próximo.

CVE-2025-62690LOWOpen redirect in error page when link opened in new tabEPSS 0.1%CVE-2026-22545LOWPassword Change Bypass via Auth Switch EndpointEPSS 0.1%CVE-2026-75025MEDIUMMattermost Desktop local network access from server-rendered contentEPSS 0.1%CVE-2026-3590MEDIUMRace Condition in Guest Magic Link Authentication Allows Token ReuseEPSS 0.1%CVE-2023-5339MEDIUMMattermost Desktop logs all keystrokes during initial run after fresh installation EPSS 0.1%CVE-2025-59480MEDIUMInadequate validation of SSO redirect credentials permits credential theftEPSS 0.1%CVE-2026-4286LOWPlaybooks Plugin fails to validate team transfers, allowing unauthorized removal of member access via playbook updateEPSS 0.1%CVE-2026-3495LOWUnescaped variables during error page compositionEPSS 0.1%CVE-2026-4273LOWInsufficient token rotation validation in remote cluster invite confirmationEPSS 0.1%CVE-2026-4274MEDIUMInsufficient authorization in shared channel membership sync grants team-level access instead of channel-level accessEPSS 0.1%CVE-2026-4339MEDIUMSSRF via unvalidated attachment URLs in Mattermost Agents plugin MCP serverEPSS 0.1%CVE-2026-28735MEDIUMGitHub OAuth Scope ValidationEPSS 0.1%CVE-2026-6333LOWSSRF via Host Header Spoofing in Custom Slash CommandsEPSS 0.1%CVE-2026-1628MEDIUMMattermost allows external websites to open within the app, exposing preload functionality to non-trusted sites.EPSS 0.1%CVE-2026-12284LOWMattermost Desktop App Missing IPC Sender Validation in Calls Leave HandlerEPSS 0.1%CVE-2026-28741MEDIUMCSRF Protection Bypass Allows Updating a User's Authentication MethodEPSS 0.1%CVE-2026-10542MEDIUMPlaybooks channel action update validation issueEPSS 0.1%CVE-2026-3113MEDIUMmmctl export download command doesn’t restrict permissions to created file to file ownerEPSS 0.1%CVE-2026-27659MEDIUMCSRF vulnerability in UpdateAccessControlPolicyActiveStatus endpointEPSS 0.1%CVE-2024-11358MEDIUMInsecure Android File Provider PathsEPSS 0.1%