FlawAtlas
Search the atlas
CVE-2025-3227 Moderate

Mattermost allows unauthorized channel member management through playbook runs in github.com/mattermost/mattermost-server

Mattermost allows unauthorized channel member management through playbook runs in github.com/mattermost/mattermost-server

Exploit probability 0.2%
Published July 28, 2025
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

76 explicit affected versions

Go github.com/mattermost/mattermost-server
Go github.com/mattermost/mattermost-server/v5
Go github.com/mattermost/mattermost-server/v6
Go github.com/mattermost/mattermost/server/v8
Go github.com/mattermost/mattermost-server
Go github.com/mattermost/mattermost/server/v8

1 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2025-3227

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions in playbook runs, allowing authenticated users without the 'Manage Channel Members' permission to add or remove users from public and private channels by manipulating playbook run participants when the run is linked to a channel.

View original source
Open Source Vulnerabilities GO-2025-3772

Mattermost allows unauthorized channel member management through playbook runs in github.com/mattermost/mattermost-server

View original source
Open Source Vulnerabilities GHSA-qwwm-c582-82rx

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions in playbook runs, allowing authenticated users without the 'Manage Channel Members' permission to add or remove users from public and private channels by manipulating playbook run participants when the run is linked to a channel.

View original source

05 / REFERENCES

Further evidence