Launch Week Day 1: Announcing Security Design Review
LOW 2.2 Go

Mattermost has Insufficiently Protected Credentials

GHSA-4fwj-8595-wp25 · CVE-2025-6227 · GO-2025-3818

Published · Modified

Description

Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which allows a user that intercepts both invite and password to send synchronization payloads to the server that originally created the invite via the REST API.

Ready to move

Start Securing

Free, no credit card | First findings in minutes