Team Membership Vulnerability in Mattermost by Mattermost
CVE-2025-14350
What is CVE-2025-14350?
Certain versions of Mattermost exhibit a vulnerability where authenticated users can improperly validate team membership. By posting channel shortlinks and analyzing the response from the API, users can potentially discover team existence and their corresponding URLs. This raises concerns about information disclosure that could be leveraged for further exploitation. It is crucial for Mattermost users to be aware of this issue and consider updating to unaffected versions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Mattermost 11.1.0 <= 11.1.2
Mattermost 10.11.0 <= 10.11.9
Mattermost 11.2.0 <= 11.2.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved