CVE 2.2 LOW

Invite token is used as part of the secure communication_CVE-2025-6227

2.2 / 10
LOW
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N

Description

Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which allows a user that intercepts both invite and password to send synchronization payloads to the server that originally created the invite via the REST API.

Basic Information

ID CVE-2025-6227
Source Mattermost
Published Jul 18, 2025 at 11:39
Modified Jul 18, 2025 at 13:44

Affected Product

Vendor Mattermost
Product Mattermost
Version 10.5.0
Affected Versions Mattermost Mattermost 10.5.0
Mattermost Mattermost 9.11.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.