Session Persistence After User-to-Bot Conversion
Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalate their privileges depending on the permissions granted to the bot.
02 / AFFECTED SOFTWARE
Affected packages
26 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Mattermost fails to invalidate all active sessions when converting a user to a bot in github.com/mattermost/mattermost-server
Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalate their privileges depending on the permissions granted to the bot.
Mattermost versions 9.11.x <= 9.11.6, 10.4.x <= 10.4.1 fail to invalidate all active sessions when converting a user to a bot, with allows the converted user to escalate their privileges depending on the permissions granted to the bot.
05 / REFERENCES
Further evidence
- https://github.com/advisories/GHSA-rhvr-6w8c-6v7w
- https://github.com/mattermost/mattermost/commit/faa7e4f2ea0cca2fd2aba271912b9fc3be788842
- https://mattermost.com/security-updates
- https://nvd.nist.gov/vuln/detail/CVE-2025-1412
- https://github.com/mattermost/mattermost
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/1xxx/CVE-2025-1412.json