CVE-2025-1792

LOW

Mattermost <10.7.0, <10.5.3, <9.11.12 - Info Disclosure

Title source: llm
STIX 2.1

Description

Mattermost versions 10.7.x <= 10.7.0, 10.5.x <= 10.5.3, 9.11.x <= 9.11.12 fail to properly enforce access controls for guest users accessing channel member information, allowing authenticated guest users to view metadata about members of public channels via the channel members API endpoint.

References (1)

Core 1
Core References

Scores

CVSS v3 3.1
EPSS 0.0014
EPSS Percentile 33.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (2)
mattermost/mattermost 10.6.0-rc1 - 10.7.1Go
mattermost/mattermost_server 9.11.0 - 9.11.13
Published May 30, 2025
Tracked Since Feb 18, 2026