Skip to content

x/vulndb: potential Go vuln in github.com/mattermost/mattermost/server/v8: GHSA-wgvp-jj4w-88hf #3797

@GoVulnBot

Description

@GoVulnBot

Advisory GHSA-wgvp-jj4w-88hf references a vulnerability in the following Go modules:

Module
github.com/mattermost/mattermost-server
github.com/mattermost/mattermost-server/v5
github.com/mattermost/mattermost-server/v6
github.com/mattermost/mattermost/server/v8

Description:
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly validate channel membership when retrieving playbook run metadata, allowing authenticated users who are playbook members but not channel members to access sensitive information about linked private channels including channel name, display name, and participant count through the run metadata API endpoint.

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/mattermost/mattermost-server
      versions:
        - fixed: 0.0.0-20250513065225-4ae5d647fb88
        - introduced: 9.11.0+incompatible
        - fixed: 9.11.16+incompatible
        - introduced: 10.5.0+incompatible
        - fixed: 10.5.6+incompatible
        - introduced: 10.6.0+incompatible
        - fixed: 10.6.6+incompatible
        - introduced: 10.7.0+incompatible
        - fixed: 10.7.3+incompatible
        - introduced: 10.8.0+incompatible
        - fixed: 10.8.1+incompatible
      vulnerable_at: 10.8.0+incompatible
    - module: github.com/mattermost/mattermost-server/v5
      vulnerable_at: 5.39.3
    - module: github.com/mattermost/mattermost-server/v6
      vulnerable_at: 6.7.2
    - module: github.com/mattermost/mattermost/server/v8
      versions:
        - fixed: 8.0.0-20250513065225-4ae5d647fb88
summary: Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server
cves:
    - CVE-2025-47871
ghsas:
    - GHSA-wgvp-jj4w-88hf
references:
    - advisory: https://github.com/advisories/GHSA-wgvp-jj4w-88hf
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-47871
    - web: https://mattermost.com/security-updates
notes:
    - fix: 'github.com/mattermost/mattermost/server/v8: could not add vulnerable_at: could not find tagged version between introduced and fixed'
    - fix: 'github.com/mattermost/mattermost-server: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
source:
    id: GHSA-wgvp-jj4w-88hf
    created: 2025-06-30T21:05:04.448345222Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions