github.com/mattermost/mattermost/server/v8 vulnerabilities
CVEs whose affected-version data names the github.com/mattermost/mattermost/server/v8 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
33 CVEsRSS
CVE-2026-3433Medium· 4.3Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel
CVE-2026-6739Medium· 6.7Mattermost doesn't require system-level permission when patching protected default system roles
Mattermost doesn't require system-level permission when patching protected default system roles
CVE-2026-6689Medium· 4.3Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation
CVE-2026-7184Medium· 6.5Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations
CVE-2026-6961High· 7.6Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync
CVE-2026-7387High· 8.8Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints
CVE-2026-6046Medium· 5.3Mattermost doesn't validate that a username returned during bot registration belongs to a bot account
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account
CVE-2025-1792Low· 3.1Mattermost fails to properly enforce access controls for guest users
Mattermost fails to properly enforce access controls for guest users
CVE-2025-3611Low· 3.1Mattermost fails to properly enforce access control restrictions for System Manager roles
Mattermost fails to properly enforce access control restrictions for System Manager roles
CVE-2025-35965Medium· 6.5Mattermost Playbooks fails to validate the uniqueness and quantity of task actions
Mattermost Playbooks fails to validate the uniqueness and quantity of task actions
CVE-2025-41395Medium· 6.5Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type
Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type
CVE-2025-27936Medium· 5.3Mattermost vulnerable to Observable Timing Discrepancy
Mattermost vulnerable to Observable Timing Discrepancy
CVE-2025-2475Medium· 5.4Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm
Mattermost vulnerable to Incorrect Implementation of Authentication Algorithm
CVE-2025-32093Medium· 4.7Mattermost Fails to Restrict Certain Operations on System Admins
Mattermost Fails to Restrict Certain Operations on System Admins
CVE-2025-25279Critical· 9.9PoCMattermost allows reading arbitrary files related to importing boards
Mattermost allows reading arbitrary files related to importing boards
CVE-2025-20086Medium· 6.5Mattermost fails to properly validate post props
Mattermost fails to properly validate post props
CVE-2025-20088Medium· 6.5Mattermost fails to properly validate post props
Mattermost fails to properly validate post props
CVE-2025-22445Low· 3.5Mattermost has Improper Check for Unusual or Exceptional Conditions
Mattermost has Improper Check for Unusual or Exceptional Conditions
CVE-2025-20033Medium· 4.3Mattermost Improper Validation of Specified Type of Input vulnerability
Mattermost Improper Validation of Specified Type of Input vulnerability
CVE-2024-47401Medium· 4.3Mattermost Server vulnerable to application crash from attacker-generated large response
Mattermost Server vulnerable to application crash from attacker-generated large response
CVE-2024-46872Medium· 4.6Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery
Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery
CVE-2024-10241Medium· 4.3Mattermost Server allows user to get private channel names
Mattermost Server allows user to get private channel names
CVE-2024-47003Medium· 5.4Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events
CVE-2024-1949Low· 2.6Mattermost race condition
Mattermost race condition
CVE-2024-1952Low· 3.1Mattermost incorrectly allows access individual posts
Mattermost incorrectly allows access individual posts
CVE-2024-23493Medium· 4.3Mattermost leaks details of AD/LDAP groups of a teams
Mattermost leaks details of AD/LDAP groups of a teams
CVE-2024-24988Medium· 4.3Mattermost denial of service through long emoji value
Mattermost denial of service through long emoji value
CVE-2024-1402Medium· 4.3Mattermost vulnerable to denial of service via large number of emoji reactions
Mattermost vulnerable to denial of service via large number of emoji reactions
CVE-2023-6458High· 7.1Mattermost Injection vulnerability
Mattermost Injection vulnerability
CVE-2023-6459Medium· 5.3Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability
Mattermost Exposure of Sensitive Information to an Unauthorized Actor vulnerability