Description
Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper input validation on post actions which allows an attacker to run a playbook checklist task command as another user via creating and sharing a deceptive post action that unexpectedly runs a slash command in some arbitrary channel.
No analysis available yet.
Remediation
Vendor Solution
Update Mattermost to versions 9.7.0, 9.5.4, 9.6.2, 8.1.13 or higher.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-36002 | Mattermost versions 9.5.x <= 9.5.3, 9.6.x <= 9.6.1 and 8.1.x <= 8.1.12 fail to perform proper input validation on post actions which allows an attacker to run a playbook checklist task command as another user via creating and sharing a deceptive post action that unexpectedly runs a slash command in some arbitrary channel. |
References
| Link | Providers |
|---|---|
| https://mattermost.com/security-updates |
|
History
Tue, 30 Sep 2025 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Mattermost mattermost Server
|
|
| CPEs | cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Mattermost mattermost Server
|
Status: PUBLISHED
Assigner: Mattermost
Published:
Updated: 2024-08-02T03:37:03.667Z
Reserved: 2024-05-23T10:57:59.907Z
Link: CVE-2024-36255
Updated: 2024-08-02T03:37:03.667Z
Status : Analyzed
Published: 2024-05-26T14:15:10.060
Modified: 2025-09-30T15:29:54.477
Link: CVE-2024-36255
No data.
OpenCVE Enrichment
Updated: 2025-07-12T15:42:39Z
Weaknesses
EUVD