blob: 197b298e486da969a7e2fe0b25d26ba0827e0754 [file]
id: GO-2025-4254
modules:
- module: github.com/mattermost/mattermost-plugin-calls
versions:
- fixed: 1.10.0
vulnerable_at: 1.9.2
summary: Mattermost has CSRF vulnerability via Calls Widget page in github.com/mattermost/mattermost-plugin-calls
cves:
- CVE-2025-62190
ghsas:
- GHSA-gmx5-frv9-9m9f
references:
- advisory: https://github.com/advisories/GHSA-gmx5-frv9-9m9f
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-62190
- fix: https://github.com/mattermost/mattermost-plugin-calls/commit/429cfaf2a301a369414d1ca18a3364e85901c8d1
- web: https://github.com/mattermost/mattermost-plugin-calls/releases/tag/v1.10.0
- web: https://mattermost.com/security-updates
source:
id: GHSA-gmx5-frv9-9m9f
created: 2025-12-29T19:23:29.516033966Z
review_status: UNREVIEWED