Mattermost allows remote actor to create/update/delete posts in arbitrary channels
High severity
GitHub Reviewed
Published
Aug 1, 2024
to the GitHub Advisory Database
•
Updated Jul 9, 2025
Package
Affected versions
< 5.3.2-0.20240619142046-8181a9ddffc0
Patched versions
5.3.2-0.20240619142046-8181a9ddffc0
>= 9.5.0, < 9.5.7
>= 9.7.0, < 9.7.6
>= 9.8.0, < 9.8.2
= 9.9.0
< 8.0.0-20240619142046-8181a9ddffc0
9.5.7
9.7.6
9.8.2
9.9.1
8.0.0-20240619142046-8181a9ddffc0
Description
Published by the National Vulnerability Database
Aug 1, 2024
Published to the GitHub Advisory Database
Aug 1, 2024
Reviewed
Aug 2, 2024
Last updated
Jul 9, 2025
Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6, 9.7.x <= 9.7.5, 9.8.x <= 9.8.1 fail to properly validate synced posts, when shared channels are enabled, which allows a malicious remote to create/update/delete arbitrary posts in arbitrary channels
References