LOW 3.3 Go
Mattermost fail to prompt for explicit approval before adding a team admin to a private channel
GHSA-cw7q-5cgc-h3h9 · BIT-mattermost-2025-27715 · CVE-2025-27715 · GO-2025-3555
Published · Modified
Description
Mattermost versions 9.11.x <= 9.11.8 fail to prompt for explicit approval before adding a team admin to a private channel, which team admins to joining private channels via crafted permalink links without explicit consent from them.
References
Ready to move
Start Securing
Free, no credit card | First findings in minutes