CVE 3.5 LOW

SSRF via Host Header Spoofing in Custom Slash Commands_CVE-2026-6333

3.5 / 10
LOW
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:N/I:L/A:N

Description

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response URLs for custom slash commands which allows an authenticated attacker to redirect slash command responses to an attacker-controlled server via a spoofed Host header.. Mattermost Advisory ID: MMSA-2026-00582

Basic Information

ID CVE-2026-6333
Source Mattermost
Published May 18, 2026 at 08:41

Affected Product

Vendor Mattermost
Product Mattermost
Version 11.5.0
Affected Versions Mattermost Mattermost 11.5.0
Mattermost Mattermost 10.11.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.