go

github.com/mattermost/mattermost-server

View on go registry
100 Total advisories
100 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/mattermost/mattermost-server is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

LOW 3.8
Go

CVE-2026-8823

Mattermost has an Incorrect Authorization issue

MEDIUM 6.4
Go

CVE-2026-6062

Mattermost doesn't validate channel ownership of an existing subscription before applying edits

MEDIUM 5.4
Go

CVE-2026-5139

Mattermost doesn't enforce administrator authorization on the {{setDefaultInstance}} call within the {{/gitlab connect}} command handler

MEDIUM 6.4
Go

CVE-2026-6673

Mattermost doesn't authenticate Atlassian Connect installed callbacks, allowing a remote unauthenticated attacker to inject a rogue sharedSecret

MEDIUM 4.3
Go

CVE-2026-9162

Mattermost doesn't invalidate cached authentication state for active WebSocket connections during global session revocation

LOW 3.8
Go

CVE-2026-8074

Mattermost doesn't enforce bot-specific permission checks on the user active status endpoint

MEDIUM 6.7
Go

CVE-2026-6739

Mattermost doesn't require system-level permission when patching protected default system roles

MEDIUM 4.7
Go

CVE-2025-32093

Mattermost Fails to Restrict Certain Operations on System Admins

MEDIUM 5.3
Go

CVE-2026-6046

Mattermost doesn't validate that a username returned during bot registration belongs to a bot account

MEDIUM 4.3
Go

CVE-2026-6689

Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation

MEDIUM 4.3
Go

CVE-2026-3433

Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel

MEDIUM 5.4
Go

CVE-2025-27933

Mattermost allows members with permission to convert public channels to private and convert private to public

MEDIUM 6.5
Go

CVE-2022-4045

Denial of service in Mattermost

HIGH 7.6
Go

CVE-2026-6961

Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync

HIGH 8.8
Go

CVE-2026-7387

Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints

MEDIUM 6.5
Go

CVE-2026-7184

Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations

UNKNOWN
Go

CVE-2026-7184

Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6961

Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-7387

Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6689

Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3433

Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6046

Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6739

Mattermost doesn't require system-level permission when patching protected default system roles in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-1792

Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-3611

Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2024-24988

Mattermost denial of service through long emoji value in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2024-23493

Mattermost leaks details of AD/LDAP groups of a teams in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2024-1952

Mattermost incorrectly allows access individual posts in github.com/mattermost/mattermost-server

HIGH 7.5
Go

CVE-2026-5308

Mattermost doesn't enforce request body size limits on plugin HTTP endpoints

MEDIUM 5.3
Go

CVE-2026-4635

Mattermost doesn't archive the channel before removing persistent notifications

MEDIUM 6.5
Go

CVE-2026-4915

Mattermost doesn't filter nil elements from outgoing webhook attachment payloads before processing

HIGH 7.1
Go

CVE-2026-3473

Mattermost doesn't validate file ownership and access control

MEDIUM 4.3
Go

CVE-2026-4646

Mattermost doesn't validate user-supplied input in API request handlers

MEDIUM 6.5
Go

CVE-2026-5755

Mattermost doesn't validate the TIFF IFD offset in the image header before allocating memory

HIGH 7.5
Go

CVE-2026-5740

Mattermost doesn't properly validate msgpack-encoded WebSocket frames before memory allocation

MEDIUM 4.3
Go

CVE-2026-3636

Mattermost doesn't sanitize team member data when returned via API to users without elevated permissions

MEDIUM 5.4
Go

CVE-2026-28735

Mattermost allows authenticated users to gain access to private repositories

UNKNOWN
Go

CVE-2026-4635

Mattermost doesn't archive the channel before removing persistent notifications in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-28735

Mattermost allows authenticated users to gain access to private repositories in github.com/mattermost/mattermost-plugin-github

UNKNOWN
Go

CVE-2026-4646

Mattermost doesn't validate user-supplied input in API request handlers in github.com/mattermost/mattermost-plugin-github

UNKNOWN
Go

CVE-2026-5308

Mattermost doesn't enforce request body size limits on plugin HTTP endpoints in github.com/mattermost/mattermost-plugin-github

UNKNOWN
Go

CVE-2026-4915

Mattermost doesn't filter nil elements from outgoing webhook attachment payloads before processing in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3473

Mattermost doesn't validate file ownership and access control in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-5740

Mattermost doesn't properly validate msgpack-encoded WebSocket frames before memory allocation in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-5755

Mattermost doesn't validate the TIFF IFD offset in the image header before allocating memory in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3636

Mattermost doesn't sanitize team member data when returned via API to users without elevated permissions in github.com/mattermost/mattermost-server

LOW 3.1
Go

CVE-2026-6334

Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow

LOW 3.1
Go

CVE-2026-4053

Mattermost doesn't enforce the PostEditTimeLimit on non-message post fields

MEDIUM 6.5
Go

CVE-2026-3590

Mattermost has session spoofing due to lack of single-use consumption of guest magic link tokens enforcement

LOW 3.8
Go

CVE-2026-3495

Mattermost doesn't escape some variables that could contain malicious content during error page composition

MEDIUM 4.3
Go

CVE-2026-4054

Mattermost doesn't validate the response body of proxied images

MEDIUM 4.3
Go

CVE-2026-3637

Mattermost doesn't check the create_post channel permission during post edit operations

MEDIUM 6.5
Go

CVE-2026-6345

Mattermost doesn't prevent disclosure of created user password

LOW 2.7
Go

CVE-2026-27769

Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace

LOW 3.7
Go

CVE-2026-4273

Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation

MEDIUM 4.3
Go

CVE-2026-28732

Mattermost doesn't enforce slash command trigger-word uniqueness during command updates

MEDIUM 4.3
Go

CVE-2026-6339

Mattermost doesn't validate the X-Requested-With header on the burn-on-read reveal endpoint

LOW 3.5
Go

CVE-2026-6333

Mattermost doesn't validate the Host header when constructing response URLs for custom slash command

MEDIUM 4.3
Go

CVE-2026-2325

Mattermost doesn't limit the size of the request body on the start meeting API endpoint

UNKNOWN
Go

CVE-2026-6345

Mattermost doesn't prevent disclosure of created user password in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6339

Mattermost doesn't validate the X-Requested-With header on the burn-on-read reveal endpoint in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-28732

Mattermost doesn't enforce slash command trigger-word uniqueness during command updates in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6333

Mattermost doesn't validate the Host header when constructing response URLs for custom slash command in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3637

Mattermost doesn't check the create_post channel permission during post edit operations in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-27769

Mattermost doesn't validate whether users were correctly owned by the correct Connected Workspace in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3114

Mattermost doesn't validate decompressed archive entry sizes during file extraction in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-27659

Mattermost doesn't properly validate CSRF tokens in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6343

Mattermost doesn't check public/private permissions in github.com/mattermost/mattermost-plugin-playbooks

UNKNOWN
Go

CVE-2026-2325

Mattermost doesn't limit the size of the request body on the start meeting API endpoint in github.com/mattermost/mattermost-plugin-msteams-meetings

UNKNOWN
Go

CVE-2026-28741

Mattermost doesn't validate CSRF tokens on an authentication endpoint in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3495

Mattermost doesn't escape some variables that could contain malicious content during error page composition in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-4054

Mattermost doesn't validate the response body of proxied images in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3115

Mattermost allows authenticated guest users to enumerate user IDs outside their allowed visibility scope in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-4053

Mattermost doesn't enforce the PostEditTimeLimit on non-message post fields in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-4273

Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3590

Mattermost has session spoofing due to lack of single-use consumption of guest magic link tokens enforcement in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6334

Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-4286

Mattermost doesn't check if {{team_id}} was being changed when updating playbooks in github.com/mattermost/mattermost-plugin-playbooks

MEDIUM 4.3
Go

CVE-2026-28759

Mattermost does not verify remote cluster channel access when processing shared channel membership removals

HIGH 8.0
Go

CVE-2026-4858

Mattermost has a Path Traversal issue

MEDIUM 6.5
Go

CVE-2026-5163

Mattermost doesn't verify channel membership when processing AI-assisted message rewrites

HIGH 7.6
Go

CVE-2026-6347

Mattermost doesn't sanitize sensitive configuration fields in the Mattermost Calls plugin

MEDIUM 5.7
Go

CVE-2026-27656

Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw

HIGH 8.7
Go

CVE-2026-6346

Mattermost doesn't sanitize sensitive configuration fields before including them in support packet generation

MEDIUM 4.3
Go

CVE-2026-6340

Mattermost doesn't validate 7zip archive structure before processing

UNKNOWN
Go

CVE-2026-4274

Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-27656

Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6340

Mattermost doesn't validate 7zip archive structure before processing in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-4858

Mattermost has a Path Traversal issue in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6346

Mattermost doesn't sanitize sensitive configuration fields before including them in support packet generation in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-28759

Mattermost does not verify remote cluster channel access when processing shared channel membership removals in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-5163

Mattermost doesn't verify channel membership when processing AI-assisted message rewrites in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-20719

Mattermost: Authenticated DoS through failure to prevent rendering of external SVGs on link embeds in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6347

Mattermost doesn't sanitize sensitive configuration fields in the Mattermost Calls plugin in github.com/mattermost/mattermost-plugin-calls

MEDIUM 5.0
Go

CVE-2026-3113

Mattermost doesn't set permissions on downloaded bulk export

UNKNOWN
Go

CVE-2026-3113

Mattermost doesn't set permissions on downloaded bulk export in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3112

Mattermost allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3108

Mattermost allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequences in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-4055

Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server

MEDIUM 4.3
Go

CVE-2026-26246

Mattermost fails to bound memory allocation when processing PSD image files

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes