VYPR
Unrated severityNVD Advisory· Published Jun 26, 2026· Updated Jun 26, 2026

Client4 fails to validate path parameters

CVE-2026-13426

Description

The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path parameters when constructing API route paths which allows an attacker to redirect API calls to unintended endpoints via crafted IDs containing path traversal components. Mattermost Advisory ID: MMSA-2025-00532

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.