Skip to content

x/vulndb: potential Go vuln in github.com/mattermost/mattermost-server: GHSA-hm95-jx66-g2gh #3960

@GoVulnBot

Description

@GoVulnBot

Advisory GHSA-hm95-jx66-g2gh references a vulnerability in the following Go modules:

Module
github.com/mattermost/mattermost-server

Description:
Mattermost versions 10.5.x <= 10.5.9 fail to properly validate redirect URLs which allows attackers to redirect users to malicious sites via crafted OAuth login URLs.

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/mattermost/mattermost-server
      versions:
        - introduced: 10.5.0+incompatible
        - fixed: 10.5.10+incompatible
      non_go_versions:
        - fixed: 8.0.0-202508080704-39bd251fe4f600
      vulnerable_at: 10.5.10-rc2+incompatible
summary: Mattermost Open Redirect vulnerability in github.com/mattermost/mattermost-server
cves:
    - CVE-2025-9084
ghsas:
    - GHSA-hm95-jx66-g2gh
references:
    - advisory: https://github.com/advisories/GHSA-hm95-jx66-g2gh
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-9084
    - fix: https://github.com/mattermost/mattermost/commit/39bd251fe4f66b7e847fc6d653221886347ff160
    - web: https://mattermost.com/security-updates
source:
    id: GHSA-hm95-jx66-g2gh
    created: 2025-09-16T20:06:11.52600843Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions