CVE-2025-35965Medium· 6.5▾ SunlitMattermost Playbooks fails to validate the uniqueness and quantity of task actions
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.4%
0.4% → 0.4%
Mattermost versions 10.4.x <= 10.4.2, 10.5.x <= 10.5.0, 9.11.x <= 9.11.10 fail to validate the uniqueness and quantity of task actions within the UpdateRunTaskActions GraphQL operation, which allows an attacker to create task items containing an excessive number of actions triggered by specific posts, overloading the server and leading to a denial-of-service (DoS) condition.
github.com/mattermost/mattermost/server/v8 < 8.0.0-20250218121836-2b5275d87136github.com/mattermost/mattermost-plugin-playbooks >= 2.0.0github.com/mattermost/mattermost/server/v8 >= 10.4.0github.com/mattermost/mattermost/server/v8 >= 10.5.0github.com/mattermost/mattermost/server/v8 >= 9.11.0github.com/mattermost/mattermost-plugin-playbooks < 1.41.0Upgrade to a patched release:
github.com/mattermost/mattermost/server/v8 8.0.0-20250218121836-2b5275d87136github.com/mattermost/mattermost-plugin-playbooks 1.41.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-41395Medium· 6.5Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type
CVE-2023-6202Medium· 4.3Mattermost Improper Access Control vulnerability
CVE-2025-22445Low· 3.5Mattermost has Improper Check for Unusual or Exceptional Conditions
CVE-2024-46872Medium· 4.6Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery
CVE-2024-47401Medium· 4.3Mattermost Server vulnerable to application crash from attacker-generated large response
CVE-2024-10241Medium· 4.3Mattermost Server allows user to get private channel names