Loading HuntDB...

GHSA-vvpg-55p7-5h8w

GitHub Security Advisory

Mattermost did not properly restrict channel creation

✓ GitHub Reviewed LOW Has CVE

Advisory Details

Mattermost versions 9.9.x <= 9.9.0, 9.5.x <= 9.5.6 fail to properly restrict channel creation which allows a malicious remote to create arbitrary channels, when shared channels were enabled.

Affected Packages

Go github.com/mattermost/mattermost/server/v8
Affected versions: 9.5.0 (fixed in 9.5.7)
Go github.com/mattermost/mattermost/server/v8
Affected versions: 9.9.0 (fixed in 9.9.1)
Go github.com/mattermost/mattermost/server/v8
Affected versions: 0 (fixed in 8.0.0-20240626164322-c758cecaf30c)
Go github.com/mattermost/mattermost-server
Affected versions: 9.9.0 (fixed in 9.9.1)
Go github.com/mattermost/mattermost-server/v5
Affected versions: 0 (fixed in 5.3.2-0.20240626164322-c758cecaf30c)
Go github.com/mattermost/mattermost-server/v6
Affected versions: 0 (fixed in 6.0.0-20240626164322-c758cecaf30c)
Go github.com/mattermost/mattermost-server
Affected versions: 9.5.0 (fixed in 9.5.7)

Related CVEs

Key Information

GHSA ID
GHSA-vvpg-55p7-5h8w
Published
August 1, 2024 3:32 PM
Last Modified
July 25, 2025 3:45 PM
CVSS Score
2.5 /10
Primary Ecosystem
Go
Primary Package
github.com/mattermost/mattermost/server/v8
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 2, 2025 6:46 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.