VYPR
Moderate severityNVD Advisory· Published Jun 20, 2025· Updated Jun 23, 2025

Unauthorized Guest user access to Playbook

CVE-2025-3228

Description

Mattermost versions 10.5.x <= 10.5.5, 9.11.x <= 9.11.15, 10.8.x <= 10.8.0, 10.7.x <= 10.7.2, 10.6.x <= 10.6.5 fail to properly retrieve requestorInfo from playbooks handler for guest users which allows an attacker access to the playbook run.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/mattermost/mattermost-serverGo
< 0.0.0-20250520060012-d0380305ef7a0.0.0-20250520060012-d0380305ef7a
github.com/mattermost/mattermost/server/v8Go
< 8.0.0-20250520060012-d0380305ef7a8.0.0-20250520060012-d0380305ef7a
github.com/mattermost/mattermost/server/v8Go
>= 10.5.0, < 10.5.610.5.6
github.com/mattermost/mattermost/server/v8Go
>= 9.11.0, < 9.11.169.11.16
github.com/mattermost/mattermost/server/v8Go
>= 10.8.0, < 10.8.110.8.1
github.com/mattermost/mattermost/server/v8Go
>= 10.7.0, < 10.7.310.7.3
github.com/mattermost/mattermost/server/v8Go
>= 10.6.0, < 10.6.610.6.6

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.