go

github.com/mattermost/mattermost-plugin-playbooks

View on go registry
12 Total advisories
12 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/mattermost/mattermost-plugin-playbooks is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

MEDIUM 6.5
Go

CVE-2025-41395

Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type

LOW 3.1
Go

CVE-2025-41423

Mattermost Playbooks fails to properly validate permissions

MEDIUM 6.5
Go

CVE-2025-35965

Mattermost Playbooks fails to validate the uniqueness and quantity of task actions

MEDIUM 4.3
Go

CVE-2026-6343

Mattermost doesn't check public/private permissions

LOW 3.1
Go

CVE-2026-4286

Mattermost doesn't check if {{team_id}} was being changed when updating playbooks

UNKNOWN
Go

CVE-2026-6343

Mattermost doesn't check public/private permissions in github.com/mattermost/mattermost-plugin-playbooks

UNKNOWN
Go

CVE-2026-4286

Mattermost doesn't check if {{team_id}} was being changed when updating playbooks in github.com/mattermost/mattermost-plugin-playbooks

MEDIUM 4.3
Go

CVE-2026-26304

Mattermost fails to verify run_create permission for empty playbookId

UNKNOWN
Go

CVE-2026-26304

Mattermost fails to verify run_create permission for empty playbookId in github.com/mattermost/mattermost-plugin-playbooks

UNKNOWN
Go

CVE-2025-41423

Mattermost Playbooks fails to properly validate permissions in github.com/mattermost/mattermost-plugin-playbooks

UNKNOWN
Go

CVE-2025-35965

Mattermost Playbooks fails to validate the uniqueness and quantity of task actions in github.com/mattermost/mattermost-plugin-playbooks

UNKNOWN
Go

CVE-2025-41395

Mattermost Playbooks fails to properly validate the props used by the RetrospectivePost custom post type in github.com/mattermost/mattermost-plugin-playbooks

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes