LOW 3.5 Go

Mattermost Server SSRF Vulnerability via the Agents Plugin

GHSA-vqwh-5jhh-vc9p · CVE-2025-47700 · GO-2025-3906

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Mattermost Server versions 10.5.x <= 10.5.9 utilizing the Agents plugin fail to reject empty request bodies which allows users to trick users into clicking malicious links via post actions

Ready to move

Start Securing

Free, no credit card | First findings in minutes