Mattermost versions 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly restrict API access to team information, allowing guest users to bypass permissions and view information about public teams they are not members of via a direct API call to /api/v4/teams/{team_id}.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-18094 Mattermost allows guest users to view information about public teams they are not members of
Github GHSA Github GHSA GHSA-jwhw-xf5v-qgxc Mattermost allows guest users to view information about public teams they are not members of
Fixes

Solution

Update Mattermost to versions 10.8.0, 10.5.5, 9.11.14 or higher.


Workaround

No workaround given by the vendor.

References
History

Sun, 13 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00024}

epss

{'score': 0.00028}


Tue, 08 Jul 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Mattermost
Mattermost mattermost Server
CPEs cpe:2.3:a:mattermost:mattermost_server:*:*:*:*:*:*:*:*
Vendors & Products Mattermost
Mattermost mattermost Server

Wed, 11 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 11 Jun 2025 10:45:00 +0000

Type Values Removed Values Added
Description Mattermost versions 10.5.x <= 10.5.4, 9.11.x <= 9.11.13 fail to properly restrict API access to team information, allowing guest users to bypass permissions and view information about public teams they are not members of via a direct API call to /api/v4/teams/{team_id}.
Title Mattermost Guest User Information Disclosure Vulnerability
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mattermost

Published:

Updated: 2025-06-11T13:12:40.338Z

Reserved: 2025-04-30T07:45:45.749Z

Link: CVE-2025-4128

cve-icon Vulnrichment

Updated: 2025-06-11T13:12:36.277Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-11T11:15:23.143

Modified: 2025-07-08T19:42:06.743

Link: CVE-2025-4128

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-06-24T09:51:42Z