User Data Sanitization Flaw in Mattermost
CVE-2025-11794

4.9MEDIUM

Key Information:

Vendor

Mattermost

Vendor
CVE Published:
14 November 2025

What is CVE-2025-11794?

Certain versions of Mattermost exhibit a data sanitization issue that allows system administrators to exploit the /api/v4/users/{user_id}/email/verify/member endpoint, potentially exposing sensitive user data such as password hashes and multi-factor authentication secrets. This vulnerability emphasizes the critical need for robust data handling practices to ensure user data remains secure.

Affected Version(s)

Mattermost 10.11.0 <= 10.11.3

Mattermost 10.5.0 <= 10.5.11

Mattermost 10.12.0

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Christian Iwata Nilsson
.
CVE-2025-11794 : User Data Sanitization Flaw in Mattermost