6 Total advisories
6 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/mattermost/mattermost-plugin-calls is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.6
CVE-2026-6347
Mattermost doesn't sanitize sensitive configuration fields in the Mattermost Calls plugin
UNKNOWN
CVE-2026-6347
Mattermost doesn't sanitize sensitive configuration fields in the Mattermost Calls plugin in github.com/mattermost/mattermost-plugin-calls
UNKNOWN
CVE-2025-62190
Mattermost has CSRF vulnerability via Calls Widget page in github.com/mattermost/mattermost-plugin-calls
UNKNOWN
CVE-2025-12689
Mattermost fails to check Websocket request for proper UTF-8 format potentially crashing Calls plug-in in github.com/mattermost/mattermost-plugin-calls
MEDIUM 6.5
CVE-2025-12689
Mattermost fails to check Websocket request for proper UTF-8 format potentially crashing Calls plug-in
MEDIUM 4.3
CVE-2025-62190
Mattermost has CSRF vulnerability via Calls Widget page
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes