blob: 98a6515e93c2eab566e32b0597ac2c4e92572382 [file]
id: GO-2025-3950
modules:
- module: github.com/mattermost/mattermost-server
versions:
- introduced: 10.10.0+incompatible
- fixed: 10.10.2+incompatible
vulnerable_at: 10.10.2-rc4+incompatible
- module: github.com/mattermost/mattermost-server/v5
vulnerable_at: 5.39.3
- module: github.com/mattermost/mattermost-server/v6
vulnerable_at: 6.7.2
- module: github.com/mattermost/mattermost/server/v8
non_go_versions:
- fixed: 8.0.0-20250729073403-517ae758cd02
vulnerable_at: 8.0.0-20250917143630-f10997a35168
summary: Mattermost Missing Authorization vulnerability in github.com/mattermost/mattermost-server
cves:
- CVE-2025-9076
ghsas:
- GHSA-3vcm-c42p-3hhf
references:
- advisory: https://github.com/advisories/GHSA-3vcm-c42p-3hhf
- advisory: https://nvd.nist.gov/vuln/detail/CVE-2025-9076
- web: https://mattermost.com/security-updates
source:
id: GHSA-3vcm-c42p-3hhf
created: 2025-09-17T12:14:30.54893-04:00
review_status: UNREVIEWED