Launch Week Day 1: Announcing Security Design Review
LOW 3.5 Go

Mattermost Lack of Access Control Validation

GHSA-pwvr-grqg-7vp2 · CVE-2025-49810 · GO-2025-3903

Published · Modified

Description

Mattermost versions 10.5.x <= 10.5.8 fail to validate access controls at time of access which allows user to read a thread via AI posts

Ready to move

Start Securing

Free, no credit card | First findings in minutes