Mattermost versions 10.11.x <= 10.11.6 and Mattermost GitHub plugin versions <=2.4.0 fail to validate plugin bot identity in reaction forwarding which allows attackers to hijack the GitHub reaction feature to make users add reactions to arbitrary GitHub objects via crafted notification posts.
References
| Link | Resource |
|---|---|
| https://mattermost.com/security-updates |
Configurations
No configuration.
History
17 Dec 2025, 13:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-17 13:15
Updated : 2025-12-18 15:08
NVD link : CVE-2025-13352
Mitre link : CVE-2025-13352
CVE.ORG link : CVE-2025-13352
JSON object : View
Products Affected
No product.
CWE
CWE-1287
Improper Validation of Specified Type of Input
