Medium severity4.3OSV Advisory· Published Dec 24, 2025· Updated Jun 17, 2026
CVE-2025-13767
CVE-2025-13767
Description
Mattermost versions 11.1.x <= 11.1.0, 11.0.x <= 11.0.5, 10.12.x <= 10.12.3, 10.11.x <= 10.11.7 fails to validate user channel membership when attaching Mattermost posts as comments to Jira issues, which allows an authenticated attacker with access to the Jira plugin to read post content and attachments from channels they do not have access to.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/mattermost/mattermost/server/v8Go | < 8.0.0-20251121122154-b57c297c6d7 | 8.0.0-20251121122154-b57c297c6d7 |
github.com/mattermost/mattermost-serverGo | >= 10.11.0, < 10.11.8 | 10.11.8 |
github.com/mattermost/mattermost-serverGo | >= 10.12.0, < 10.12.4 | 10.12.4 |
github.com/mattermost/mattermost-serverGo | >= 11.0.0, < 11.0.6 | 11.0.6 |
github.com/mattermost/mattermost-serverGo | >= 11.1.0, < 11.1.1 | 11.1.1 |
Affected products
6@mattermost/[email protected], @mattermost/[email protected], @mattermost/[email protected], …+ 1 more
- (no CPE)range: @mattermost/[email protected], @mattermost/[email protected], @mattermost/[email protected], …
- cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*range: >=10.11.0,<10.11.8
- ghsa-coords4 versionspkg:golang/github.com/mattermost/mattermost-serverpkg:golang/github.com/mattermost/mattermost/server/v8pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2016.0
>= 10.11.0, < 10.11.8+ 3 more
- (no CPE)range: >= 10.11.0, < 10.11.8
- (no CPE)range: < 8.0.0-20251121122154-b57c297c6d7
- (no CPE)range: < 0.0.20260226T182644-150000.1.149.1
- (no CPE)range: < 0.0.20260723T184607-160000.1.1
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-fmqf-pmcm-8cx9ghsaADVISORY
- mattermost.com/security-updatesnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2025-13767ghsaADVISORY
- github.com/mattermost/mattermost/commit/b57c297c6d7ae6812d85e32a625806ac9555deeeghsaWEB
- github.com/mattermost/mattermost/pull/34551ghsaWEB
- pkg.go.dev/vuln/GO-2026-4259ghsaWEB
News mentions
0No linked articles in our index yet.