HTML Injection Vulnerability in Mattermost Confluence Plugin
CVE-2025-13523
7.7HIGH
Key Information:
- Vendor
Mattermost
- Vendor
- CVE Published:
- 6 February 2026
What is CVE-2025-13523?
The Mattermost Confluence plugin prior to version 1.7.0 contains a flaw that improperly escapes user-controlled display names during HTML template rendering. This vulnerability allows authenticated Confluence users who have malicious display names to execute arbitrary JavaScript code in the browsers of unsuspecting victims. By sending a specially crafted OAuth2 connection link, which renders the attacker's unescaped display name in the victim's browser, the attacker can exploit this vulnerability to perform various malicious actions. For detailed security updates, please refer to the Mattermost advisory at MMSA-2025-00557.
Affected Version(s)
Mattermost Confluence Plugin 0 < 1.7.0
Mattermost Confluence Plugin 1.7.0