Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rendering which allows authenticated Confluence users with malicious display names to execute arbitrary JavaScript in victim browsers via sending a specially crafted OAuth2 connection link that, when visited, renders the attacker's display name without proper sanitization. Mattermost Advisory ID: MMSA-2025-00557

Project Subscriptions

No data.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-ffx7-34p2-vm3w Mattermost Confluence plugin doesn't properly escape user-controlled display names in HTML template rendering
Fixes

Solution

Update Mattermost Confluence plugin to versions 1.7.0 or higher.


Workaround

No workaround given by the vendor.

References
History

Fri, 06 Feb 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 06 Feb 2026 16:00:00 +0000

Type Values Removed Values Added
Description Mattermost Confluence plugin version <1.7.0 fails to properly escape user-controlled display names in HTML template rendering which allows authenticated Confluence users with malicious display names to execute arbitrary JavaScript in victim browsers via sending a specially crafted OAuth2 connection link that, when visited, renders the attacker's display name without proper sanitization. Mattermost Advisory ID: MMSA-2025-00557
Title Cross-Site Scripting (XSS) via Unescaped Display Names in Mattermost Confluence Plugin OAuth2 Flow
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2026-02-06T16:23:06.496Z

Reserved: 2025-11-21T19:29:16.051Z

Link: CVE-2025-13523

cve-icon Vulnrichment

Updated: 2026-02-06T16:22:51.348Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-06T16:16:13.370

Modified: 2026-02-06T21:57:22.450

Link: CVE-2025-13523

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses