Loading HuntDB...

GHSA-jq3g-xqpx-37x3

GitHub Security Advisory

Mattermost failed to properly validate synced reactions

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly validate synced reactions, when shared channels are enabled, which allows a malicious remote to create arbitrary reactions on arbitrary posts

Affected Packages

Go github.com/mattermost/mattermost/server/v8
Affected versions: 9.5.0 (fixed in 9.5.7)
Go github.com/mattermost/mattermost/server/v8
Affected versions: 9.9.0 (fixed in 9.9.1)

Related CVEs

Key Information

GHSA ID
GHSA-jq3g-xqpx-37x3
Published
August 1, 2024 3:32 PM
Last Modified
November 18, 2024 4:26 PM
CVSS Score
5.0 /10
Primary Ecosystem
Go
Primary Package
github.com/mattermost/mattermost/server/v8
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 2, 2025 6:46 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.