Skip to content

x/vulndb: potential Go vuln in github.com/mattermost/mattermost-server/v6: GHSA-mqcj-8c2g-h97q #4122

@GoVulnBot

Description

@GoVulnBot

Advisory GHSA-mqcj-8c2g-h97q references a vulnerability in the following Go modules:

Module
github.com/mattermost/mattermost-server
github.com/mattermost/mattermost-server/v5
github.com/mattermost/mattermost-server/v6

Description:
Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11 fail to properly validate team membership permissions in the Add Channel Member API, which allows users from one team to access user metadata and channel membership information from other teams via the API endpoint.

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/mattermost/mattermost-server
      versions:
        - introduced: 10.5.0+incompatible
        - fixed: 10.5.12+incompatible
        - introduced: 10.11.0+incompatible
        - fixed: 10.11.4+incompatible
      non_go_versions:
        - fixed: 8.0.0-20250905150616-ba86dfc5876b
      vulnerable_at: 10.11.4-rc3+incompatible
    - module: github.com/mattermost/mattermost-server/v5
      non_go_versions:
        - fixed: 5.3.2-0.20250905150616-ba86dfc5876b
      vulnerable_at: 5.39.3
    - module: github.com/mattermost/mattermost-server/v6
      vulnerable_at: 6.7.2
summary: Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server
cves:
    - CVE-2025-11777
ghsas:
    - GHSA-mqcj-8c2g-h97q
references:
    - advisory: https://github.com/advisories/GHSA-mqcj-8c2g-h97q
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-11777
    - fix: https://github.com/mattermost/mattermost/commit/98acefe911dd9de7edf47a7d825dd99f53141a52
    - fix: https://github.com/mattermost/mattermost/commit/ba86dfc5876b354b9d3c20ff45c08ca6f8426149
    - fix: https://github.com/mattermost/mattermost/commit/d72d437f1567ba0b639b6e4fd73bab06c51baab5
    - web: https://mattermost.com/security-updates
source:
    id: GHSA-mqcj-8c2g-h97q
    created: 2025-11-14T16:03:12.273885935Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions