CVE-2025-41443: Mattermost has a Missing Authorization vulnerability
Mattermost versions 10.5.x <= 10.5.10, 10.11.x <= 10.11.2 fail to properly validate guest user permissions when accessing channel information which allows guest users to discover active public channels and their metadata via the /api/v4/teams/{team_id}/channels/ids
endpoint
References
- github.com/advisories/GHSA-7cr3-38jm-6p45
- github.com/mattermost/mattermost
- github.com/mattermost/mattermost/commit/e8c7e7d0252bbf1e098aae4a5ea05d945afd7e70
- github.com/mattermost/mattermost/pull/31327
- github.com/mattermost/mattermost/pull/33778
- mattermost.com/security-updates
- nvd.nist.gov/vuln/detail/CVE-2025-41443
Code Behaviors & Features
Detect and mitigate CVE-2025-41443 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →