Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-4g87-9x45-cx2h Mattermost fails to sanitize team email addresses
Fixes

Solution

Update Mattermost to versions 11.1.0, 11.0.3, 10.12.2, 10.11.5, 10.5.13 or higher.


Workaround

No workaround given by the vendor.

References
History

Fri, 28 Nov 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 28 Nov 2025 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost
Vendors & Products Mattermost
Mattermost mattermost

Thu, 27 Nov 2025 16:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 11.0.x <= 11.0.2, 10.12.x <= 10.12.1, 10.11.x <= 10.11.4, 10.5.x <= 10.5.12 fail to sanitize team email addresses to be visible only to Team Admins, which allows any authenticated user to view team email addresses via the GET /api/v4/channels/{channel_id}/common_teams endpoint
Title Information Disclosure in Common Teams API
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2025-11-28T15:20:44.142Z

Reserved: 2025-10-31T17:28:45.000Z

Link: CVE-2025-12559

cve-icon Vulnrichment

Updated: 2025-11-28T15:20:29.673Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2025-11-27T17:15:46.530

Modified: 2025-11-28T23:11:55.537

Link: CVE-2025-12559

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-11-28T08:51:21Z