FlawAtlas
Search the atlas
CVE-2025-47871 Moderate

Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server

Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server

Exploit probability 0.2%
Published July 28, 2025
Required by Not available
Last source change March 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

76 explicit affected versions

Go github.com/mattermost/mattermost-server
Go github.com/mattermost/mattermost-server/v5
Go github.com/mattermost/mattermost-server/v6
Go github.com/mattermost/mattermost/server/v8
Go github.com/mattermost/mattermost-server
Go github.com/mattermost/mattermost/server/v8

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities GO-2025-3797

Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server

View original source
Open Source Vulnerabilities GHSA-wgvp-jj4w-88hf

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly validate channel membership when retrieving playbook run metadata, allowing authenticated users who are playbook members but not channel members to access sensitive information about linked private channels including channel name, display name, and participant count through the run metadata API endpoint.

View original source
Open Source Vulnerabilities CVE-2025-47871

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly validate channel membership when retrieving playbook run metadata, allowing authenticated users who are playbook members but not channel members to access sensitive information about linked private channels including channel name, display name, and participant count through the run metadata API endpoint.

View original source

05 / REFERENCES

Further evidence