Launch Week Day 1: Announcing Security Design Review
LOW 3.5 Go

Mattermost Server SSRF Vulnerability via the Agents Plugin

GHSA-vqwh-5jhh-vc9p · CVE-2025-47700 · GO-2025-3906

Published · Modified

Description

Mattermost Server versions 10.5.x <= 10.5.9 utilizing the Agents plugin fail to reject empty request bodies which allows users to trick users into clicking malicious links via post actions

Ready to move

Start Securing

Free, no credit card | First findings in minutes