Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-27715


Mattermost versions 9.11.x <= 9.11.8 fail to prompt for explicit approval before adding a team admin to a private channel, which team admins to joining private channels via crafted permalink links without explicit consent from them.


Published

2025-03-21T09:15:13.100

Last Modified

2025-03-27T15:01:03.360

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 3.3 (LOW)

Weaknesses
  • Type: Secondary
    CWE-863
  • Type: Primary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application mattermost mattermost_server < 9.11.9 Yes

References