Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server
02 / AFFECTED SOFTWARE
Affected packages
35 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark which allows an attacker who knows the IDs of deleted files to obtain metadata of the files via bookmark creation.
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server
Mattermost versions 10.5.x <= 10.5.1, 9.11.x <= 9.11.9 fail to check if a file has been deleted when creating a bookmark which allows an attacker who knows the IDs of deleted files to obtain metadata of the files via bookmark creation.
05 / REFERENCES
Further evidence
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/2xxx/CVE-2025-2424.json
- https://mattermost.com/security-updates
- https://nvd.nist.gov/vuln/detail/CVE-2025-2424
- https://github.com/advisories/GHSA-wwhj-pw6h-f8hw
- https://github.com/mattermost/mattermost/commit/68c11e9ecb7129f7d3e0e67277f0a5924a8cbe06
- https://github.com/mattermost/mattermost
- https://pkg.go.dev/vuln/GO-2025-3611