Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wvcv-9xpm-7mqc

Опубликовано: 18 мая 2026
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Mattermost doesn't enforce slash command trigger-word uniqueness during command updates

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash command trigger-word uniqueness during command updates which allows an authenticated team member with Manage Own Slash Commands permission to hijack and impersonate existing system or custom slash commands via editing their own slash command trigger to an already-registered trigger through the command update API. Mattermost Advisory ID: MMSA-2026-00597

Пакеты

Наименование

github.com/mattermost/mattermost/server/v8

go
Затронутые версииВерсия исправления

>= 11.5.0, < 11.5.2

11.5.2

Наименование

github.com/mattermost/mattermost/server/v8

go
Затронутые версииВерсия исправления

>= 10.11.0, < 10.11.14

10.11.14

Наименование

github.com/mattermost/mattermost/server/v8

go
Затронутые версииВерсия исправления

>= 11.4.0, < 11.4.4

11.4.4

Наименование

github.com/mattermost/mattermost/server/v8

go
Затронутые версииВерсия исправления

< 8.0.0-20260306123948-f5fe8ded6b63

8.0.0-20260306123948-f5fe8ded6b63

Наименование

github.com/mattermost/mattermost-server

go
Затронутые версииВерсия исправления

< 5.3.2-0.20260306123948-f5fe8ded6b63

5.3.2-0.20260306123948-f5fe8ded6b63

EPSS

Процентиль: 5%
0.00152
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 4.3
nvd
3 месяца назад

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 Fail to enforce slash command trigger-word uniqueness during command updates which allows an authenticated team member with Manage Own Slash Commands permission to hijack and impersonate existing system or custom slash commands via editing their own slash command trigger to an already-registered trigger through the command update API. Mattermost Advisory ID: MMSA-2026-00597

CVSS3: 4.3
debian
3 месяца назад

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 1 ...

EPSS

Процентиль: 5%
0.00152
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-863