Skip to content

x/vulndb: potential Go vuln in github.com/mattermost/mattermost/server/v8: GHSA-ff85-qw3h-g9vp #4129

@GoVulnBot

Description

@GoVulnBot

Advisory GHSA-ff85-qw3h-g9vp references a vulnerability in the following Go modules:

Module
github.com/mattermost/mattermost-server
github.com/mattermost/mattermost-server/v5
github.com/mattermost/mattermost-server/v6
github.com/mattermost/mattermost/server/v8

Description:
Mattermost versions 10.11.x <= 10.11.3, 10.5.x <= 10.5.11, 10.12.x <= 10.12.0 fail to validate the relationship between the post being updated and the MSTeams plugin OAuth flow which allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL.

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/mattermost/mattermost-server
      versions:
        - introduced: 10.5.0+incompatible
        - fixed: 10.5.12+incompatible
        - introduced: 10.11.0+incompatible
        - fixed: 10.11.4+incompatible
        - introduced: 10.12.0+incompatible
        - fixed: 10.12.1+incompatible
      vulnerable_at: 10.12.1-rc1+incompatible
    - module: github.com/mattermost/mattermost-server/v5
      vulnerable_at: 5.39.3
    - module: github.com/mattermost/mattermost-server/v6
      vulnerable_at: 6.7.2
    - module: github.com/mattermost/mattermost/server/v8
      versions:
        - fixed: 8.0.0-20250929212932-a41db04d2746
summary: |-
    Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams
    plugin OAuth redirect URL in github.com/mattermost/mattermost-server
cves:
    - CVE-2025-55073
ghsas:
    - GHSA-ff85-qw3h-g9vp
references:
    - advisory: https://github.com/advisories/GHSA-ff85-qw3h-g9vp
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-55073
    - fix: https://github.com/mattermost/mattermost/commit/375ce229f4923205394d8f27925372b2cbf28130
    - fix: https://github.com/mattermost/mattermost/commit/6c288aa62bb3343183ec1d0a06360d14aa0193e9
    - fix: https://github.com/mattermost/mattermost/commit/a41db04d2746ab549d056db4ede4cd803f64989c
    - fix: https://github.com/mattermost/mattermost/commit/b822cea06bf5683a176e2c92711241bd29cd9389
    - fix: https://github.com/mattermost/mattermost/commit/e47349ea0fc072ee1dfb196d9bb1c8fd1a589224
    - web: https://mattermost.com/security-updates
notes:
    - fix: 'github.com/mattermost/mattermost/server/v8: could not add vulnerable_at: could not find tagged version between introduced and fixed'
source:
    id: GHSA-ff85-qw3h-g9vp
    created: 2025-11-17T18:02:50.257077292Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions