Loading HuntDB...

GHSA-762g-9p7f-mrww

GitHub Security Advisory

Mattermost Server Path Traversal vulnerability that leads to Cross-Site Request Forgery

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Mattermost versions 9.10.x <= 9.10.2, 9.11.x <= 9.11.1, 9.5.x <= 9.5.9 fail to sanitize user inputs in the frontend that are used for redirection which allows for a one-click client-side path traversal that is leading to CSRF in Playbooks

Affected Packages

Go github.com/mattermost/mattermost/server/v8
Affected versions: 0 (fixed in 8.0.0-20240926115259-20ed58906adc)

Related CVEs

Key Information

GHSA ID
GHSA-762g-9p7f-mrww
Published
October 29, 2024 9:30 AM
Last Modified
November 4, 2024 9:22 PM
CVSS Score
5.0 /10
Primary Ecosystem
Go
Primary Package
github.com/mattermost/mattermost/server/v8
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 2, 2025 6:46 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.