LOW 3.5 Go
Mattermost Server SSRF Vulnerability via the Agents Plugin
GHSA-vqwh-5jhh-vc9p · CVE-2025-47700 · GO-2025-3906
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Mattermost Server versions 10.5.x <= 10.5.9 utilizing the Agents plugin fail to reject empty request bodies which allows users to trick users into clicking malicious links via post actions
Ready to move
Start Securing
Free, no credit card | First findings in minutes