Skip to content

x/vulndb: potential Go vuln in github.com/mattermost/mattermost/server/v8: GHSA-x3hx-ch7p-8xgg #4131

@GoVulnBot

Description

@GoVulnBot

Advisory GHSA-x3hx-ch7p-8xgg references a vulnerability in the following Go modules:

Module
github.com/mattermost/mattermost-server
github.com/mattermost/mattermost-server/v5
github.com/mattermost/mattermost-server/v6
github.com/mattermost/mattermost/server/v8

Description:
Mattermost versions < 11.0 fail to properly enforce the "Allow users to view archived channels" setting which allows regular users to access archived channel content and files via the "Open in Channel" functionality from followed threads

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/mattermost/mattermost-server
      versions:
        - fixed: 11.0.0-alpha.1+incompatible
      vulnerable_at: 10.12.3+incompatible
    - module: github.com/mattermost/mattermost-server/v5
      vulnerable_at: 5.39.3
    - module: github.com/mattermost/mattermost-server/v6
      vulnerable_at: 6.7.2
    - module: github.com/mattermost/mattermost/server/v8
      versions:
        - fixed: 8.0.0-20250815165020-c8d66301415d
summary: Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server
cves:
    - CVE-2025-41436
ghsas:
    - GHSA-x3hx-ch7p-8xgg
references:
    - advisory: https://github.com/advisories/GHSA-x3hx-ch7p-8xgg
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-41436
    - fix: https://github.com/mattermost/mattermost/commit/c8d66301415d5b447df0e829bdbaa92e8a83ecf8
    - web: https://mattermost.com/security-updates
notes:
    - fix: 'github.com/mattermost/mattermost/server/v8: could not add vulnerable_at: could not find tagged version between introduced and fixed'
source:
    id: GHSA-x3hx-ch7p-8xgg
    created: 2025-11-17T18:03:09.511575055Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions