Dependency scanning
Check whether github.com/mattermost/mattermost-server/v5 is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-7184
Mattermost doesn't sanitize the Remote Cluster API response on PATCH operations in github.com/mattermost/mattermost-server
CVE-2026-6961
Mattermost doesn't sanitize FileInfo.Name received from federated peers during shared channel file sync in github.com/mattermost/mattermost-server
CVE-2026-7387
Mattermost doesn't require role-management authorization when setting the scheme_admin flag on group syncable link and patch endpoints in github.com/mattermost/mattermost-server
CVE-2026-6689
Mattermost doesn't enforce PermissionInviteUser when setting AllowOpenInvite or AllowedDomains during team creation in github.com/mattermost/mattermost-server
CVE-2026-3433
Mattermost doesn't restrict role_updated websocket event broadcasts to members of the affected team or channel in github.com/mattermost/mattermost-server
CVE-2026-6046
Mattermost doesn't validate that a username returned during bot registration belongs to a bot account in github.com/mattermost/mattermost-server
CVE-2026-6739
Mattermost doesn't require system-level permission when patching protected default system roles in github.com/mattermost/mattermost-server
CVE-2025-1792
Mattermost fails to properly enforce access controls for guest users in github.com/mattermost/mattermost-server
CVE-2025-3611
Mattermost fails to properly enforce access control restrictions for System Manager roles in github.com/mattermost/mattermost-server
CVE-2024-24988
Mattermost denial of service through long emoji value in github.com/mattermost/mattermost-server
CVE-2024-23493
Mattermost leaks details of AD/LDAP groups of a teams in github.com/mattermost/mattermost-server
CVE-2024-1952
Mattermost incorrectly allows access individual posts in github.com/mattermost/mattermost-server
CVE-2026-4915
Mattermost doesn't filter nil elements from outgoing webhook attachment payloads before processing in github.com/mattermost/mattermost-server
CVE-2026-5740
Mattermost doesn't properly validate msgpack-encoded WebSocket frames before memory allocation in github.com/mattermost/mattermost-server
CVE-2026-6345
Mattermost doesn't prevent disclosure of created user password in github.com/mattermost/mattermost-server
CVE-2026-6339
Mattermost doesn't validate the X-Requested-With header on the burn-on-read reveal endpoint in github.com/mattermost/mattermost-server
CVE-2026-28732
Mattermost doesn't enforce slash command trigger-word uniqueness during command updates in github.com/mattermost/mattermost-server
CVE-2026-6333
Mattermost doesn't validate the Host header when constructing response URLs for custom slash command in github.com/mattermost/mattermost-server
CVE-2026-3637
Mattermost doesn't check the create_post channel permission during post edit operations in github.com/mattermost/mattermost-server
CVE-2026-3114
Mattermost doesn't validate decompressed archive entry sizes during file extraction in github.com/mattermost/mattermost-server
CVE-2026-27659
Mattermost doesn't properly validate CSRF tokens in github.com/mattermost/mattermost-server
CVE-2026-6343
Mattermost doesn't check public/private permissions in github.com/mattermost/mattermost-plugin-playbooks
CVE-2026-28741
Mattermost doesn't validate CSRF tokens on an authentication endpoint in github.com/mattermost/mattermost-server
CVE-2026-3495
Mattermost doesn't escape some variables that could contain malicious content during error page composition in github.com/mattermost/mattermost-server
CVE-2026-3115
Mattermost allows authenticated guest users to enumerate user IDs outside their allowed visibility scope in github.com/mattermost/mattermost-server
CVE-2026-4273
Mattermost doesn't validate that the RefreshedToken differs from the original invite token during remote cluster invite confirmation in github.com/mattermost/mattermost-server
CVE-2026-3590
Mattermost has session spoofing due to lack of single-use consumption of guest magic link tokens enforcement in github.com/mattermost/mattermost-server
CVE-2026-6334
Mattermost doesn't enforce client identity binding during the OAuth authorization code redemption flow in github.com/mattermost/mattermost-server
CVE-2026-4286
Mattermost doesn't check if {{team_id}} was being changed when updating playbooks in github.com/mattermost/mattermost-plugin-playbooks
CVE-2026-4274
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server
CVE-2026-27656
Mattermost allows attackers to take over arbitrary user accounts via overly permissive substring matching flaw in github.com/mattermost/mattermost-server
CVE-2026-6340
Mattermost doesn't validate 7zip archive structure before processing in github.com/mattermost/mattermost-server
CVE-2026-6346
Mattermost doesn't sanitize sensitive configuration fields before including them in support packet generation in github.com/mattermost/mattermost-server
CVE-2026-28759
Mattermost does not verify remote cluster channel access when processing shared channel membership removals in github.com/mattermost/mattermost-server
CVE-2026-5163
Mattermost doesn't verify channel membership when processing AI-assisted message rewrites in github.com/mattermost/mattermost-server
CVE-2026-20719
Mattermost: Authenticated DoS through failure to prevent rendering of external SVGs on link embeds in github.com/mattermost/mattermost-server
CVE-2026-3112
Mattermost allows system administrators to read arbitrary host files via malicious AdvancedLoggingJSON configuration in github.com/mattermost/mattermost-server
CVE-2026-3108
Mattermost allows attackers to manipulate administrator terminals via crafted messages containing ANSI and OSC escape sequences in github.com/mattermost/mattermost-server
CVE-2026-4055
Mattermost has an Incorrect Authorization issue in github.com/mattermost/mattermost-server
CVE-2026-26246
Mattermost fails to bound memory allocation when processing PSD image files in github.com/mattermost/mattermost-server
CVE-2026-25783
Mattermost fails to properly validate User-Agent header tokens in github.com/mattermost/mattermost-server
CVE-2026-2456
Mattermost fails to limit the size of responses from integration action endpoints in github.com/mattermost/mattermost-server
CVE-2026-22545
Mattermost fails to validate user's authentication method when processing account auth type switch in github.com/mattermost/mattermost-server
CVE-2026-21386
Mattermost fails to use consistent error responses when handling the /mute command in github.com/mattermost/mattermost-server
CVE-2026-4265
Mattermost fails to validate team-specific upload_file permissions in github.com/mattermost/mattermost-server
CVE-2026-2455
Mattermost fails to canonicalize IPv4-mapped IPv6 addresses before reserved IP validation in github.com/mattermost/mattermost-server
CVE-2026-2578
Mattermost fails to preserve the redacted state of burn-on-read posts during deletion in github.com/mattermost/mattermost-server
CVE-2026-24458
Mattermost fails to properly handle very long passwords in github.com/mattermost/mattermost-server
CVE-2026-25780
Mattermost fails to bound memory allocation when processing DOC files in github.com/mattermost/mattermost-server
CVE-2026-2457
Mattermost allows attackers to spoof permalink embeds in github.com/mattermost/mattermost-server
CVE-2026-24692
Mattermost fails to properly enforce read permissions in search API endpoints in github.com/mattermost/mattermost-server
CVE-2026-2463
Mattermost fails to filter invite IDs based on user permissions in github.com/mattermost/mattermost-server
CVE-2026-2458
Mattermost allows a removed team member to enumerate all public channels within a private team in github.com/mattermost/mattermost-server
CVE-2025-14273
Mattermost with Jira plugin enabled has Incorrect Implementation of Authentication Algorithm in github.com/mattermost/mattermost-plugin-jira
CVE-2025-13352
Mattermost GitHub Plugin Bot Identity Validation Bypass Allows Arbitrary GitHub Reaction Injection in github.com/mattermost/mattermost
CVE-2025-13324
Mattermost has an Invite Token Replay Vulnerability via Channel Membership Manipulation in github.com/mattermost/mattermost
CVE-2025-62690
Mattermost has missing redirect URL validation in github.com/mattermost/mattermost
CVE-2025-13870
Mattermost fails to validate user permissions in Boards in github.com/mattermost/mattermost
CVE-2025-12421
Mattermost fails to to verify the token used during code exchange in github.com/mattermost/mattermost-server
CVE-2025-12756
Mattermost fails to validate user permissions when deleting comments in Boards in github.com/mattermost/mattermost
CVE-2025-12559
Mattermost fails to sanitize team email addresses in github.com/mattermost/mattermost-server
CVE-2025-12419
Mattermost fails to properly validate OAuth state tokens during OpenID Connect authentication in github.com/mattermost/mattermost-server
CVE-2025-41436
Mattermost allows regular users to access archived channel content and files in github.com/mattermost/mattermost-server
CVE-2018-21258
Mattermost Server is vulnerable to a Denial of Service attack through `invite_people` command in github.com/mattermost/mattermost-server
CVE-2025-55070
Mattermost does not enforce MFA on WebSocket connections in github.com/mattermost/mattermost-server
CVE-2025-55073
Mattermost allows an attacker to edit arbitrary posts via a crafted MSTeams plugin OAuth redirect URL in github.com/mattermost/mattermost-server
CVE-2025-55074
Mattermost allows other users to determine when users had read channels via channel member objects in github.com/mattermost/mattermost-server
CVE-2025-11794
Mattermost allows system administrators to access password hashes and MFA secrets in github.com/mattermost/mattermost-server
CVE-2025-11776
Mattermost fails to properly restrict access to archived channel search API in github.com/mattermost/mattermost
CVE-2025-11777
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost
CVE-2025-9081
Mattermost boards plugin fails to restrict download access to files in github.com/mattermost/mattermost-plugin-boards
CVE-2025-9079
Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server
CVE-2025-6465
Mattermost Fails to Sanitize File Names in github.com/mattermost/mattermost-server
CVE-2025-46702
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server
CVE-2025-3228
Mattermost allows an unauthorized Guest user access to Playbook in github.com/mattermost/mattermost-server
CVE-2025-47871
Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server
CVE-2025-4981
Mattermost allows authenticated users to write files to arbitrary locations in github.com/mattermost/mattermost-server
CVE-2025-3230
Mattermost fails to properly invalidate personal access tokens upon user deactivation in github.com/mattermost/mattermost-server
CVE-2025-3913
Mattermost improperly allows team administrators to modify team invites in github.com/mattermost/mattermost-server
CVE-2025-2571
Mattermost fails to clear Google OAuth credentials in github.com/mattermost/mattermost-server
CVE-2025-2527
Mattermost Fails to Verify User's Permissions When Accessing Groups in github.com/mattermost/mattermost-server
CVE-2025-58075
Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server
CVE-2025-54499
Mattermost has an Observable Timing Discrepancy vulnerability in github.com/mattermost/mattermost-server
CVE-2025-10545
Mattermost has an Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server
CVE-2025-58073
Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server
CVE-2025-41410
Mattermost has a Missing Authorization vulnerability in github.com/mattermost/mattermost-server
CVE-2025-9076
Mattermost Missing Authorization vulnerability in github.com/mattermost/mattermost-server
CVE-2025-9084
Mattermost Open Redirect vulnerability in github.com/mattermost/mattermost-server
CVE-2025-9078
Mattermost makes Use of Weak Hash in github.com/mattermost/mattermost-server
CVE-2025-9072
Mattermost Open Redirect vulnerability in github.com/mattermost/mattermost-server
CVE-2025-8402
Mattermost has Potential Server Crash due to Unvalidated Import Data in github.com/mattermost/mattermost-server
CVE-2025-47700
Mattermost Server SSRF Vulnerability via the Agents Plugin in github.com/mattermost/mattermost-server
CVE-2025-8023
Mattermost Fails to Sanitize Path Traversal Sequences in github.com/mattermost/mattermost-server
CVE-2025-47870
Mattermost Does Not Sanitize the Team Invite ID in github.com/mattermost/mattermost-server
CVE-2025-49222
Mattermost Fails to Validate Remote Cluster Upload Sessions in github.com/mattermost/mattermost-server
CVE-2025-49810
Mattermost Lack of Access Control Validation in github.com/mattermost/mattermost-server
CVE-2025-53971
Mattermost Fails to Properly Validate Team Role Modification in github.com/mattermost/mattermost-server
CVE-2025-36530
Mattermost Fails to Validate File Paths in github.com/mattermost/mattermost-server
CVE-2025-6233
Mattermost Path Traversal vulnerability in github.com/mattermost/mattermost-server
CVE-2025-6226
Mattermost Missing Authentication for Critical Function in github.com/mattermost/mattermost-server
Browse more Go advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes