Skip to content

x/vulndb: potential Go vuln in github.com/mattermost/mattermost/server/v8: GHSA-v8fr-vxmw-6mf6 #3796

@GoVulnBot

Description

@GoVulnBot

Advisory GHSA-v8fr-vxmw-6mf6 references a vulnerability in the following Go modules:

Module
github.com/mattermost/mattermost-server
github.com/mattermost/mattermost-server/v5
github.com/mattermost/mattermost-server/v6
github.com/mattermost/mattermost/server/v8

Description:
Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly enforce channel member management permissions when adding participants to playbook runs. This allows authenticated users with member-level permissions to bypass system admin restrictions and add or remove users to/from private channels via the playbook run participants feature, even when the 'Manage Members' permission has been explicitly removed. This can lead to unauthorized access to sensitive channel content and allow guest users to gain channel management privileg...

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/mattermost/mattermost-server
      versions:
        - fixed: 0.0.0-20250513065225-4ae5d647fb88
        - introduced: 9.11.0+incompatible
        - fixed: 9.11.16+incompatible
        - introduced: 10.5.0+incompatible
        - fixed: 10.5.6+incompatible
        - introduced: 10.6.0+incompatible
        - fixed: 10.6.6+incompatible
        - introduced: 10.7.0+incompatible
        - fixed: 10.7.3+incompatible
        - introduced: 10.8.0+incompatible
        - fixed: 10.8.1+incompatible
      vulnerable_at: 10.8.0+incompatible
    - module: github.com/mattermost/mattermost-server/v5
      vulnerable_at: 5.39.3
    - module: github.com/mattermost/mattermost-server/v6
      vulnerable_at: 6.7.2
    - module: github.com/mattermost/mattermost/server/v8
      versions:
        - fixed: 8.0.0-20250513065225-4ae5d647fb88
summary: Mattermost Incorrect Authorization vulnerability in github.com/mattermost/mattermost-server
cves:
    - CVE-2025-46702
ghsas:
    - GHSA-v8fr-vxmw-6mf6
references:
    - advisory: https://github.com/advisories/GHSA-v8fr-vxmw-6mf6
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-46702
    - fix: https://github.com/mattermost/mattermost/commit/31142f101e3cce6171e2b6cb4980a1aa8eaefae0
    - fix: https://github.com/mattermost/mattermost/commit/4ae5d647fb8893d77dccbb57d114855939a775ce
    - web: https://mattermost.com/security-updates
notes:
    - fix: 'github.com/mattermost/mattermost/server/v8: could not add vulnerable_at: could not find tagged version between introduced and fixed'
    - fix: 'github.com/mattermost/mattermost-server: could not add vulnerable_at: cannot auto-guess when fixed version is 0.0.0 pseudo-version'
source:
    id: GHSA-v8fr-vxmw-6mf6
    created: 2025-06-30T21:05:02.67329846Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions