Post Management Vulnerability in Mattermost by Mattermost Inc.
CVE-2025-24839
3.1LOW
Summary
A security issue in Mattermost allows unauthorized users to trigger AI bot responses through Wrangler posts. With certain versions of the Mattermost and Wrangler plugins enabled, users can exploit an oversight by adding an 'activate_ai' property to their posts, thus activating the AI without proper permissions. This vulnerability emphasizes the need for stringent access controls within Mattermost's plugin architecture to prevent abuse and ensure proper user authentication.
Affected Version(s)
Mattermost 10.5.0 <= 10.5.1
Mattermost 10.4.0 <= 10.4.3
Mattermost 9.11.0 <= 9.11.9
References
CVSS V3.1
Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Juho Forsén