CVE-2025-10545: Mattermost has an Incorrect Authorization vulnerability
Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when adding channel members which allows guest users to add any team members to their private channels via the /api/v4/channels/{channel_id}/members
endpoint
References
- github.com/advisories/GHSA-424h-xj87-m937
- github.com/mattermost/mattermost
- github.com/mattermost/mattermost/commit/fb9c583f5e466a566a5122154ef337bbf2238902
- github.com/mattermost/mattermost/commit/ff30b84049f0193f0570d30e46cffc3602298c67
- github.com/mattermost/mattermost/pull/31319
- github.com/mattermost/mattermost/pull/33827
- mattermost.com/security-updates
- nvd.nist.gov/vuln/detail/CVE-2025-10545
Code Behaviors & Features
Detect and mitigate CVE-2025-10545 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →