go

github.com/mattermost/mattermost-server/v5

View on go registry
100 Total advisories
100 Vulnerabilities
0 Malware

Dependency scanning

Check whether github.com/mattermost/mattermost-server/v5 is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

UNKNOWN
Go

CVE-2026-7184

Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6961

Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-7387

Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6689

Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3433

Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6046

Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6739

Mattermost doesn't require system-level permission when patching protected default system roles in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-1792

Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-3611

Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2024-24988

Mattermost denial of service through long emoji value in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2024-23493

Mattermost leaks details of AD/LDAP groups of a teams in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2024-1952

Mattermost incorrectly allows access individual posts in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-4915

Mattermost doesn't filter nil elements from outgoing webhook attachment payloads before processing in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-5740

Mattermost doesn't properly validate msgpack-encoded WebSocket frames before memory allocation in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6345

Mattermost doesn't prevent disclosure of created user password in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6339

Mattermost doesn't validate the X-Requested-With header on the burn-on-read reveal endpoint in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-28732

Mattermost doesn't enforce slash command trigger-word uniqueness during command updates in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6333

Mattermost doesn't validate the Host header when constructing response URLs for custom slash command in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3637

Mattermost doesn't check the create_post channel permission during post edit operations in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3114

Mattermost doesn't validate decompressed archive entry sizes during file extraction in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-27659

Mattermost doesn't properly validate CSRF tokens in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6343

Mattermost doesn't check public/private permissions in github.com/mattermost/mattermost-plugin-playbooks

UNKNOWN
Go

CVE-2026-28741

Mattermost doesn't validate CSRF tokens on an authentication endpoint in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3495

Mattermost doesn't escape some variables that could contain malicious content during error page composition in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3115

Mattermost allows authenticated guest users to enumerate user IDs outside their allowed visibility scope in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-4273

Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3590

Mattermost has session spoofing due to lack of single-use consumption of guest magic link tokens enforcement in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6334

Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-4286

Mattermost doesn't check if {{team_id}} was being changed when updating playbooks in github.com/mattermost/mattermost-plugin-playbooks

UNKNOWN
Go

CVE-2026-4274

Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-27656

Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6340

Mattermost doesn't validate 7zip archive structure before processing in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-6346

Mattermost doesn't sanitize sensitive configuration fields before including them in support packet generation in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-28759

Mattermost does not verify remote cluster channel access when processing shared channel membership removals in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-5163

Mattermost doesn't verify channel membership when processing AI-assisted message rewrites in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-20719

Mattermost: Authenticated DoS through failure to prevent rendering of external SVGs on link embeds in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3112

Mattermost allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-3108

Mattermost allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequences in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-4055

Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-26246

Mattermost fails to bound memory allocation when processing PSD image files in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-25783

Mattermost fails to properly validate User-Agent header tokens in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-2456

Mattermost fails to limit the size of responses from integration action endpoints in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-22545

Mattermost fails to validate user's authentication method when processing account auth type switch in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-21386

Mattermost fails to use consistent error responses when handling the /mute command in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-4265

Mattermost fails to validate team-specific upload_file permissions in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-2455

Mattermost fails to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-2578

Mattermost fails to preserve the redacted state of burn-on-read posts during deletion in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-24458

Mattermost fails to properly handle very long passwords in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-25780

Mattermost fails to bound memory allocation when processing DOC files in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-2457

Mattermost allows attackers to spoof permalink embeds in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-24692

Mattermost fails to properly enforce read permissions in search API endpoints in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-2463

Mattermost fails to filter invite IDs based on user permissions in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2026-2458

Mattermost allows a removed team member to enumerate all public channels within a private team in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-14273

Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira

UNKNOWN
Go

CVE-2025-13352

Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost

UNKNOWN
Go

CVE-2025-13324

Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost

UNKNOWN
Go

CVE-2025-62690

Mattermost has missing redirect URL validation in github.com/mattermost/mattermost

UNKNOWN
Go

CVE-2025-13870

Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost

UNKNOWN
Go

CVE-2025-12421

Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-12756

Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost

UNKNOWN
Go

CVE-2025-12559

Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-12419

Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-41436

Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2018-21258

Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-55070

Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-55073

Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-55074

Mattermost allows other users to determine when users had read channels via channel member objects in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-11794

Mattermost allows system administrators to access password hashes and MFA secrets in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-11776

Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost

UNKNOWN
Go

CVE-2025-11777

Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost

UNKNOWN
Go

CVE-2025-9081

Mattermost boards plugin fails to restrict download access to files in github.com/mattermost/mattermost-plugin-boards

UNKNOWN
Go

CVE-2025-9079

Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-6465

Mattermost Fails to Sanitize File Names in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-46702

Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-3228

Mattermost allows an unauthorized Guest user access to Playbook in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-47871

Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-4981

Mattermost allows authenticated users to write files to arbitrary locations in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-3230

Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-3913

Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-2571

Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-2527

Mattermost Fails to Verify User's Permissions When Accessing Groups in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-58075

Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-54499

Mattermost has an Observable Timing Discrepancy vulnerability in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-10545

Mattermost has an Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-58073

Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-41410

Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-9076

Mattermost Missing Authorization vulnerability in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-9084

Mattermost Open Redirect vulnerability in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-9078

Mattermost makes Use of Weak Hash in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-9072

Mattermost Open Redirect vulnerability in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-8402

Mattermost has Potential Server Crash due to Unvalidated Import Data in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-47700

Mattermost Server SSRF Vulnerability via the Agents Plugin in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-8023

Mattermost Fails to Sanitize Path Traversal Sequences in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-47870

Mattermost Does Not Sanitize the Team Invite ID in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-49222

Mattermost Fails to Validate Remote Cluster Upload Sessions in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-49810

Mattermost Lack of Access Control Validation in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-53971

Mattermost Fails to Properly Validate Team Role Modification in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-36530

Mattermost Fails to Validate File Paths in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-6233

Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server

UNKNOWN
Go

CVE-2025-6226

Mattermost Missing Authentication for Critical Function in github.com/mattermost/mattermost-server

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes