Impact
Mattermost versions up to 11.9, 11.0.9, 11.4.8, 11.7.7, and 10.22.11.0 do not recover from handler panics caused by malformed post‑action requests, allowing an authenticated user to crash the MS Calendar plugin process.
Affected Systems
The affected product is Mattermost, specifically the MS Calendar plugin. Vulnerable versions include any release 10.22.11.0 or earlier, 11.0.9 or earlier, 11.4.8 or earlier, 11.7.7 or earlier, and 11.9 or earlier.
Risk and Exploitability
The CVSS score is 4.3 and the EPSS score is not available. The vulnerability is not listed in CISA KEV. Attack requires an authenticated user who can send a post‑action request with an unexpected field type to trigger the non‑recoverable panic and cause a denial‑of‑service of the plugin. No remote code execution or data exfiltration is possible.
OpenCVE Enrichment