CVE 3 LOW

Mattermost GitHub Plugin allows unauthorized GitHub reactions via reaction forwarding hijacking_CVE-2025-13352

3 / 10
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N

Description

Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack the GitHub reaction feature to make users add reactions to arbitrary GitHub objects via crafted notification posts.

Basic Information

ID CVE-2025-13352
Source Mattermost
Published Dec 17, 2025 at 12:11

Affected Product

Vendor Mattermost
Product Mattermost
Version 10.11.0
Affected Versions Mattermost Mattermost 10.11.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.