Dependency scanning
Check whether github.com/mattermost/mattermost-server is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-8823
Mattermost has an Incorrect Authorization issue
CVE-2026-6062
Mattermost doesn't validate channel ownership of an existing subscription before applying edits
CVE-2026-5139
Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler
CVE-2026-6673
Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret
CVE-2026-9162
Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation
CVE-2026-8074
Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint
CVE-2026-6739
Mattermost doesn't require system-level permission when patching protected default system roles
CVE-2025-32093
Mattermost Fails to Restrict Certain Operations on System Admins
CVE-2026-6046
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account
CVE-2026-6689
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation
CVE-2026-3433
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel
CVE-2025-27933
Mattermost allows members with permission to convert public channels to private and convert private to public
CVE-2022-4045
Denial of service in Mattermost
CVE-2026-6961
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync
CVE-2026-7387
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints
CVE-2026-7184
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations
CVE-2026-7184
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server
CVE-2026-6961
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server
CVE-2026-7387
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server
CVE-2026-6689
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server
CVE-2026-3433
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server
CVE-2026-6046
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server
CVE-2026-6739
Mattermost doesn't require system-level permission when patching protected default system roles in github.com/mattermost/mattermost-server
CVE-2025-1792
Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server
CVE-2025-3611
Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server
CVE-2024-24988
Mattermost denial of service through long emoji value in github.com/mattermost/mattermost-server
CVE-2024-23493
Mattermost leaks details of AD/LDAP groups of a teams in github.com/mattermost/mattermost-server
CVE-2024-1952
Mattermost incorrectly allows access individual posts in github.com/mattermost/mattermost-server
CVE-2026-5308
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints
CVE-2026-4635
Mattermost doesn't archive the channel before removing persistent notifications
CVE-2026-4915
Mattermost doesn't filter nil elements from outgoing webhook attachment payloads before processing
CVE-2026-3473
Mattermost doesn't validate file ownership and access control
CVE-2026-4646
Mattermost doesn't validate user-supplied input in API request handlers
CVE-2026-5755
Mattermost doesn't validate the TIFF IFD offset in the image header before allocating memory
CVE-2026-5740
Mattermost doesn't properly validate msgpack-encoded WebSocket frames before memory allocation
CVE-2026-3636
Mattermost doesn't sanitize team member data when returned via API to users without elevated permissions
CVE-2026-28735
Mattermost allows authenticated users to gain access to private repositories
CVE-2026-4635
Mattermost doesn't archive the channel before removing persistent notifications in github.com/mattermost/mattermost-server
CVE-2026-28735
Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github
CVE-2026-4646
Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github
CVE-2026-5308
Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github
CVE-2026-4915
Mattermost doesn't filter nil elements from outgoing webhook attachment payloads before processing in github.com/mattermost/mattermost-server
CVE-2026-3473
Mattermost doesn't validate file ownership and access control in github.com/mattermost/mattermost-server
CVE-2026-5740
Mattermost doesn't properly validate msgpack-encoded WebSocket frames before memory allocation in github.com/mattermost/mattermost-server
CVE-2026-5755
Mattermost doesn't validate the TIFF IFD offset in the image header before allocating memory in github.com/mattermost/mattermost-server
CVE-2026-3636
Mattermost doesn't sanitize team member data when returned via API to users without elevated permissions in github.com/mattermost/mattermost-server
CVE-2026-6334
Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow
CVE-2026-4053
Mattermost doesn't enforce the PostEditTimeLimit on non-message post fields
CVE-2026-3590
Mattermost has session spoofing due to lack of single-use consumption of guest magic link tokens enforcement
CVE-2026-3495
Mattermost doesn't escape some variables that could contain malicious content during error page composition
CVE-2026-4054
Mattermost doesn't validate the response body of proxied images
CVE-2026-3637
Mattermost doesn't check the create_post channel permission during post edit operations
CVE-2026-6345
Mattermost doesn't prevent disclosure of created user password
CVE-2026-27769
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace
CVE-2026-4273
Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation
CVE-2026-28732
Mattermost doesn't enforce slash command trigger-word uniqueness during command updates
CVE-2026-6339
Mattermost doesn't validate the X-Requested-With header on the burn-on-read reveal endpoint
CVE-2026-6333
Mattermost doesn't validate the Host header when constructing response URLs for custom slash command
CVE-2026-2325
Mattermost doesn't limit the size of the request body on the start meeting API endpoint
CVE-2026-6345
Mattermost doesn't prevent disclosure of created user password in github.com/mattermost/mattermost-server
CVE-2026-6339
Mattermost doesn't validate the X-Requested-With header on the burn-on-read reveal endpoint in github.com/mattermost/mattermost-server
CVE-2026-28732
Mattermost doesn't enforce slash command trigger-word uniqueness during command updates in github.com/mattermost/mattermost-server
CVE-2026-6333
Mattermost doesn't validate the Host header when constructing response URLs for custom slash command in github.com/mattermost/mattermost-server
CVE-2026-3637
Mattermost doesn't check the create_post channel permission during post edit operations in github.com/mattermost/mattermost-server
CVE-2026-27769
Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server
CVE-2026-3114
Mattermost doesn't validate decompressed archive entry sizes during file extraction in github.com/mattermost/mattermost-server
CVE-2026-27659
Mattermost doesn't properly validate CSRF tokens in github.com/mattermost/mattermost-server
CVE-2026-6343
Mattermost doesn't check public/private permissions in github.com/mattermost/mattermost-plugin-playbooks
CVE-2026-2325
Mattermost doesn't limit the size of the request body on the start meeting API endpoint in github.com/mattermost/mattermost-plugin-msteams-meetings
CVE-2026-28741
Mattermost doesn't validate CSRF tokens on an authentication endpoint in github.com/mattermost/mattermost-server
CVE-2026-3495
Mattermost doesn't escape some variables that could contain malicious content during error page composition in github.com/mattermost/mattermost-server
CVE-2026-4054
Mattermost doesn't validate the response body of proxied images in github.com/mattermost/mattermost-server
CVE-2026-3115
Mattermost allows authenticated guest users to enumerate user IDs outside their allowed visibility scope in github.com/mattermost/mattermost-server
CVE-2026-4053
Mattermost doesn't enforce the PostEditTimeLimit on non-message post fields in github.com/mattermost/mattermost-server
CVE-2026-4273
Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation in github.com/mattermost/mattermost-server
CVE-2026-3590
Mattermost has session spoofing due to lack of single-use consumption of guest magic link tokens enforcement in github.com/mattermost/mattermost-server
CVE-2026-6334
Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow in github.com/mattermost/mattermost-server
CVE-2026-4286
Mattermost doesn't check if {{team_id}} was being changed when updating playbooks in github.com/mattermost/mattermost-plugin-playbooks
CVE-2026-28759
Mattermost does not verify remote cluster channel access when processing shared channel membership removals
CVE-2026-4858
Mattermost has a Path Traversal issue
CVE-2026-5163
Mattermost doesn't verify channel membership when processing AI-assisted message rewrites
CVE-2026-6347
Mattermost doesn't sanitize sensitive configuration fields in the Mattermost Calls plugin
CVE-2026-27656
Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw
CVE-2026-6346
Mattermost doesn't sanitize sensitive configuration fields before including them in support packet generation
CVE-2026-6340
Mattermost doesn't validate 7zip archive structure before processing
CVE-2026-4274
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server
CVE-2026-27656
Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw in github.com/mattermost/mattermost-server
CVE-2026-6340
Mattermost doesn't validate 7zip archive structure before processing in github.com/mattermost/mattermost-server
CVE-2026-4858
Mattermost has a Path Traversal issue in github.com/mattermost/mattermost-server
CVE-2026-6346
Mattermost doesn't sanitize sensitive configuration fields before including them in support packet generation in github.com/mattermost/mattermost-server
CVE-2026-28759
Mattermost does not verify remote cluster channel access when processing shared channel membership removals in github.com/mattermost/mattermost-server
CVE-2026-5163
Mattermost doesn't verify channel membership when processing AI-assisted message rewrites in github.com/mattermost/mattermost-server
CVE-2026-20719
Mattermost: Authenticated DoS through failure to prevent rendering of external SVGs on link embeds in github.com/mattermost/mattermost-server
CVE-2026-6347
Mattermost doesn't sanitize sensitive configuration fields in the Mattermost Calls plugin in github.com/mattermost/mattermost-plugin-calls
CVE-2026-3113
Mattermost doesn't set permissions on downloaded bulk export
CVE-2026-3113
Mattermost doesn't set permissions on downloaded bulk export in github.com/mattermost/mattermost-server
CVE-2026-3112
Mattermost allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration in github.com/mattermost/mattermost-server
CVE-2026-3108
Mattermost allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequences in github.com/mattermost/mattermost-server
CVE-2026-4055
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server
CVE-2026-26246
Mattermost fails to bound memory allocation when processing PSD image files
Browse more Go advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes