Loading...
Skip to main content
Go Modules

github.com/mattermost/mattermost-server Security Analysis

github.com/mattermost/mattermost-server has 15 known security vulnerabilities in Go Modules. Upgrade to version 11.6.1 or later to resolve all known issues. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.

15 Vulnerabilities

Low Immediate Risk

No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.

Recommended safe version: 11.6.1

Upgrading to 11.6.1 or later resolves all 15 known vulnerabilities in github.com/mattermost/mattermost-server. Run: go get github.com/mattermost/mattermost-server@v11.6.1

Is github.com/mattermost/mattermost-server in your project?

Check if you're affected and upgrade to 11.6.1 to stay secure.

15
Total
0
Critical
0
High
0
Medium
0
Low

Vulnerabilities

15 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.

CVE / GHSASeverityAffectedFixed In
CVE-2025-4981
Mattermost allows authenticated users to write files to arbitrary locations
CRITICAL
All versions0.0.0-20250519205859-65aec10162f6
CVE-2025-12421
Mattermost fails to to verify the token used during code exchange
CRITICAL
All versions11.0.3, 10.12.2, 10.11.5 (+1 more)
CVE-2025-12419
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication
CRITICAL
All versions10.12.2, 10.11.5, 10.5.13 (+1 more)
CVE-2017-18915
Mattermost Server server restarts may provide attackers with API access
CRITICAL
All versions3.6.7-0.20170420152529-0968e4079e0a, 3.7.5, 3.8.2
CVE-2017-18888
Mattermost Server is vulnerable to SQL Injection when executing multiple POST requests
CRITICAL
All versions4.1.2, 4.2.1, 4.3.0
CVE-2017-18885
Mattermost Server allows attackers to gain privileges by accessing unintended API endpoints with users' credentials
CRITICAL
All versions4.1.2, 4.2.1, 4.3.0
CVE-2017-18908
Mattermost Server password reset email requests can be sent to attacker-provided email addresses
CRITICAL
All versions3.9.1-rc1, 3.10.1
CVE-2017-18900
Mattermost Server is vulnerable CSV Injection
CRITICAL
All versions3.10.3, 4.0.3
CVE-2026-6347
Mattermost doesn't sanitize sensitive configuration fields in the Mattermost Calls plugin
HIGH
All versions11.5.2, 10.11.14, 11.4.4
CVE-2026-6346
Mattermost doesn't sanitize sensitive configuration fields before including them in support packet generation
HIGH
All versions5.3.2-0.20260326202606-fac92f4a71f3
CVE-2025-58073
Mattermost has a Missing Authorization vulnerability
HIGH
All versions10.11.2, 10.10.3, 10.5.11
CVE-2025-58075
Mattermost has a Missing Authorization vulnerability
HIGH
All versions10.11.2, 10.10.3, 10.5.11
CVE-2026-5308
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints
HIGH
11.6.011.6.1, 11.5.4, 11.4.5 (+1 more)
CVE-2026-5740
Mattermost doesn't properly validate msgpack-encoded WebSocket frames before memory allocation
HIGH
11.6.011.6.1, 11.5.4, 11.4.5 (+1 more)
CVE-2026-24458
Mattermost fails to properly handle very long passwords
HIGH
All versions5.3.2-0.20260129164748-7201f42d955f, 10.11.11, 11.2.3 (+1 more)

About This Data

Vulnerability data for github.com/mattermost/mattermost-server is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.

CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Check Your Dependencies

Scan your project to check if you're using a vulnerable version of github.com/mattermost/mattermost-server.

Data from OSV DatabaseUpdated daily200K+ vulnerabilities indexed