MEDIUM 4.3 Go
Mattermost Fails to Restrict Bookmark Creation and Updates in Archived Channels
GHSA-rp74-x43m-cpw3 · BIT-mattermost-2025-24920 · CVE-2025-24920 · GO-2025-3552
Published · Modified
Description
Mattermost versions 10.4.x <= 10.4.2, 10.3.x <= 10.3.3, 9.11.x <= 9.11.8, 10.5.x <= 10.5.0 fail to restrict bookmark creation and updates in archived channels, which allows authenticated users created or update bookmarked in archived channels
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes