8 Total advisories
8 Vulnerabilities
0 Malware
Dependency scanning
Check whether github.com/mattermost/mattermost-plugin-github is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 7.5
CVE-2026-5308
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints
MEDIUM 4.3
CVE-2026-4646
Mattermost doesn't validate user-supplied input in API request handlers
MEDIUM 5.4
CVE-2026-28735
Mattermost allows authenticated users to gain access to private repositories
UNKNOWN
CVE-2026-28735
Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github
UNKNOWN
CVE-2026-4646
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github
UNKNOWN
CVE-2026-5308
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github
UNKNOWN
CVE-2025-13352
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost
LOW 3.0
CVE-2025-13352
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection
Browse more Go advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes