4.1
/ 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
Description
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fail to verify that post actions invoking /share-issue-publicly were created by the Jira plugin which allowed a malicious Mattermost user to exfiltrate Jira tickets when victim users interacted with affected posts
Basic Information
ID
CVE-2025-64641
Source
Mattermost
Published
Dec 24, 2025 at 08:02
Affected Product
Vendor
Mattermost
Product
Mattermost
Version
11.1.0
Affected Versions
Mattermost Mattermost 11.1.0
Mattermost Mattermost 11.0.0
Mattermost Mattermost 10.12.0
Mattermost Mattermost 10.11.0
Mattermost Mattermost 11.0.0
Mattermost Mattermost 10.12.0
Mattermost Mattermost 10.11.0